CxJasonT / CxFlowBodgeit

CxOne PR and CxFlow webhook
0 stars 0 forks source link

CX: CVE-2021-36374 in Maven-org.apache.ant:ant and 1.8.4 @ CxFlowBodgeit.master #19

Closed CxJasonT closed 3 years ago

CxJasonT commented 3 years ago

Description

When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

MEDIUM Vulnerable Package issue exists @ org.apache.ant:ant in branch master

Vulnerability ID: CVE-2021-36374

Package Name: org.apache.ant:ant

Severity: MEDIUM

CVSS Score: 5.5

Publish Date: 2021-07-14T07:15:00

Current Package Version: 1.8.4

Remediation Upgrade Recommendation: 1.9.16

Link To SCA

Reference – NVD link