Apache Ant TAR archive denial of service vulnerability
Summary
| CVE | CVE-2021-36373 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-14 07:15:08 UTC |
| Updated | 2026-08-25 16:28:27 UTC |
| Description | When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Problem Types: CWE-130 | NVD-CWE-Other | CWE-130 CWE-130 Improper Handling of Length Parameter Inconsistency
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 4.3 | AV:N/AC:M/Au:N/C:N/I:N/A:P |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Ant | affected Apache Ant 1.9.x 1.9.15 custom | Not specified |
| CNA | Apache Software Foundation | Apache Ant | affected Apache Ant 1.10.x 1.10.10 custom | Not specified |
| CNA | Apache Software Foundation | Apache Ant | unaffected Apache Ant 1.9.0 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| lists.apache.org/thread.html/rf4bb79751a02889623195715925e4fd8932dd3c97e0ade91... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Oracle Critical Patch Update Advisory - April 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| lists.apache.org/thread.html/r54afdab05e01de970649c2d91a993f68a6b00cd73e6e34e1... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Vendor Advisory |
| Oracle Critical Patch Update Advisory - October 2021 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| lists.apache.org/thread.html/rad36f470647c5a7c02dd78c9973356d2840766d132b597b6... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Oracle Critical Patch Update Advisory - January 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - July 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Not Applicable |
| July 2021 Apache Ant Vulnerabilities in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| lists.apache.org/thread.html/r27919fd4db07c487239c1d9771f480d89ce5ee2750aa9447... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Apache Ant - Apache Ant Security Reports | af854a3a-2127-422b-91ae-364da2661108 | ant.apache.org | Patch, Vendor Advisory |
| lists.apache.org/thread.html/r544c9e8487431768465b8b2d13982c75123109bd816acf83... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: This issue is similar to https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35517 present in Apache Commons Compress which has been detected by OSS Fuzz. (en)
Additional Advisory Data
Workarounds
CNA: Apache Ant 1.9.x users should upgrade to 1.9.16 or later. Apache Ant 1.10.x users should upgrade to 1.10.11 or later.
Legacy QID Mappings
- 183912 Debian Security Update for ant (CVE-2021-36373)
- 296065 Oracle Solaris 11.4 Support Repository Update (SRU) 39.107.1 Missing (CPUOCT2021)
- 376123 IBM Installation Manager Multiple Vulnerabilities
- 501805 Alpine Linux Security Update for apache-ant
- 504580 Alpine Linux Security Update for apache-ant
- 670695 EulerOS Security Update for ant (EulerOS-SA-2021-2453)
- 670958 EulerOS Security Update for ant (EulerOS-SA-2021-2651)
- 671660 EulerOS Security Update for ant (EulerOS-SA-2022-1703)
- 752076 SUSE Enterprise Linux Security Update for ant (SUSE-SU-2022:1417-1)
- 753206 SUSE Enterprise Linux Security Update for ant (SUSE-SU-2022:1418-1)
- 900240 CBL-Mariner Linux Security Update for ant 1.10.9
- 903364 Common Base Linux Mariner (CBL-Mariner) Security Update for ant (4437)
- 980363 Java (maven) Security Update for org.apache.ant:ant (GHSA-q5r4-cfpx-h6fh)