In this case please carefully study this report and CVEs mentioned in it - these vulnerabilities are not in JaCoCo, but in Ant
and
state
Apache Ant prior to 1.9.16 and 1.10.11 were affected.
states
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files
org.jacoco.ant has a dependency on Ant with scope "provided" because org.jacoco.ant is to be used from/with Ant,
and org.jacoco.ant is compatible with different Ant versions, including vulnerable Ant versions.
In other words you can be affected by these vulnerabilities only if you use vulnerable Ant versions, i.e. prior to 1.10.11
and can not be affected if you use Ant versions that have fixes for them - e.g. latest as of today Ant 1.10.12