← Back

CVE-2021-37714

nvd nist
Published: Aug 18, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes.

Affected (24)

Show all products
1 product
Jsoup
1 product
Quarkus
13 products
Banking Trade Finance
Banking Treasury Management
Business Process Management Suite
Communications Messaging Server
Flexcube Universal Banking
Hospitality Token Proxy Service
Peoplesoft Enterprise Peopletools
Primavera Unifier
Webcenter Portal
Stream Analytics
1 product
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.14.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.2.3
Configuration C
15 vulnerable
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration E
6 vulnerable

References (28)

Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Release NotesVendor Advisory
Source: security-advisories@github.com
Release NotesVendor Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.