Apache Ant ZIP, and ZIP based, archive denial of service vulerability
Summary
| CVE | CVE-2021-36374 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-14 07:15:08 UTC |
| Updated | 2026-08-25 16:28:27 UTC |
| Description | When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Problem Types: CWE-130 | NVD-CWE-Other | CWE-130 CWE-130 Improper Handling of Length Parameter Inconsistency
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 4.3 | AV:N/AC:M/Au:N/C:N/I:N/A:P |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Ant | affected 1.4 Apache Ant* custom | Not specified |
| CNA | Apache Software Foundation | Apache Ant | affected Apache Ant 1.9.x 1.9.15 custom | Not specified |
| CNA | Apache Software Foundation | Apache Ant | affected Apache Ant 1.10.x 1.10.10 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| lists.apache.org/thread.html/rf4bb79751a02889623195715925e4fd8932dd3c97e0ade91... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Oracle Critical Patch Update Advisory - April 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - October 2021 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| lists.apache.org/thread.html/rad36f470647c5a7c02dd78c9973356d2840766d132b597b6... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Oracle Critical Patch Update Advisory - January 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - July 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| July 2021 Apache Ant Vulnerabilities in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| lists.apache.org/thread.html/r27919fd4db07c487239c1d9771f480d89ce5ee2750aa9447... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Apache Ant - Apache Ant Security Reports | af854a3a-2127-422b-91ae-364da2661108 | ant.apache.org | Patch, Vendor Advisory |
| lists.apache.org/thread.html/r544c9e8487431768465b8b2d13982c75123109bd816acf83... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/rdd5412a5b9a25aed2a02c3317052d38a97128314d50bc1ed... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Vendor Advisory |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: This issue is similar to https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36090 present in Apache Commons Compress which has been detected by OSS Fuzz. (en)
Additional Advisory Data
Workarounds
CNA: Apache Ant 1.9.x users should upgrade to 1.9.16 or later. Apache Ant 1.10.x users should upgrade to 1.10.11 or later.
Legacy QID Mappings
- 150735 Oracle WebLogic Server Multiple Vulnerabilities (CPU - OCT2023)
- 182126 Debian Security Update for ant (CVE-2021-36374)
- 296065 Oracle Solaris 11.4 Support Repository Update (SRU) 39.107.1 Missing (CPUOCT2021)
- 354116 Amazon Linux Security Advisory for ant : ALAS2-2022-1880
- 376123 IBM Installation Manager Multiple Vulnerabilities
- 501805 Alpine Linux Security Update for apache-ant
- 504580 Alpine Linux Security Update for apache-ant
- 670695 EulerOS Security Update for ant (EulerOS-SA-2021-2453)
- 670958 EulerOS Security Update for ant (EulerOS-SA-2021-2651)
- 671660 EulerOS Security Update for ant (EulerOS-SA-2022-1703)
- 752076 SUSE Enterprise Linux Security Update for ant (SUSE-SU-2022:1417-1)
- 753206 SUSE Enterprise Linux Security Update for ant (SUSE-SU-2022:1418-1)
- 87548 Oracle WebLogic Server Multiple Vulnerabilities (CPUOCT2023)
- 900240 CBL-Mariner Linux Security Update for ant 1.10.9
- 903404 Common Base Linux Mariner (CBL-Mariner) Security Update for ant (4438)
- 980362 Java (maven) Security Update for org.apache.ant:ant (GHSA-5v34-g2px-j4fw)