ZeroHour

CVE-2021-36373

CVSS 3.1
5.5 medium
EPSS
3%p84
Published
()
Modified
Description

When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

Vendors
apacheoracle
Products
ant, agile product lifecycle management, banking trade finance, banking treasury management, communications cloud native core automated test suite, communications cloud native core binding support function, communications order and service management, communications unified inventory management, enterprise repository, financial services analytical applications infrastructure, insurance policy administration, primavera gateway
Weakness
CWE-130
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.