CVE-2021-36374
בינונית 5.5
תיאור (מקור, אנגלית)
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
מדדים
- CVSS 3.1
-
5.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 3% (אחוזון 100) נכון ל-8/10/2026
- CWE
- CWE-130
מוצרים מושפעים
apache: ant; oracle: agile engineering data management; oracle: agile product lifecycle management; oracle: banking trade finance; oracle: banking treasury management; oracle: communications cloud native core automated test suite; oracle: communications cloud native core binding support function; oracle: communications diameter intelligence hub; oracle: communications order and service management; oracle: communications unified inventory management; oracle: enterprise repository; oracle: financial services analytical applications infrastructure; oracle: health sciences information manager; oracle: insurance policy administration; oracle: primavera gateway
קישורים
- https://ant.apache.org/security.html PatchVendor Advisory
- https://lists.apache.org/thread.html/rdd5412a5b9a25aed2a02c3317052d38a97128314… Mailing ListVendor Advisory
- https://ant.apache.org/security.html PatchVendor Advisory
- https://lists.apache.org/thread.html/rdd5412a5b9a25aed2a02c3317052d38a97128314… Mailing ListVendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory