SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-36373

When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs.

MEDIUM 5.5EPSS 2.53%

Does this matter?

Lower severity and a low EPSS score (2.53%). Track it; it rarely justifies an emergency change on its own.

Description

When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
2.53% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-130
Affected
apache/ant · oracle/agile product lifecycle management · oracle/banking trade finance · oracle/banking treasury management · oracle/communications cloud native core automated test suite · oracle/communications cloud native core binding support function · oracle/communications order and service management · oracle/communications unified inventory management · oracle/enterprise repository · oracle/financial services analytical applications infrastructure · oracle/insurance policy administration · oracle/primavera gateway · oracle/primavera unifier · oracle/real-time decision server · oracle/retail advanced inventory planning · oracle/retail back office · oracle/retail bulk data integration · oracle/retail central office · oracle/retail eftlink · oracle/retail extract transform and load · +12 more
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.