← Back

CVE-2021-30468

nvd nist
Published: Jun 16, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.

Affected (9)

2 products
Cxf
Tomee
3 products
Business Intelligence
Communications Element Manager
Communications Messaging Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Before 3.3.11
From 3.4.0 to 3.4.4
Version 8.0.6
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 5.5.0.0.0
Version 5.9.0.0.0
Version 8.2.2
Version 8.1

References (30)

Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.