Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-30468

Опубликовано: 16 июн. 2021
Источник: redhat
CVSS3: 7.5

Описание

A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.

Отчет

In OpenShift Container Platform (OCP) the openshift4/ose-logging-elasticsearch6 container bundles the vulnerable version of apache-cxf, but OCP 4.6 is Out Of Support Scope (OOSS) for Moderate and Low impact vulnerabilities because it is now in the Maintenance Phase of the support, hence this component is marked as ooss. Starting in 4.7 this component is delivered as part of the OpenShift Logging product (openshift-logging/elasticsearch6-rhel8 container) and is not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Red Hat BPM Suite 6cxf-rt-rs-json-basicNot affected
Red Hat Decision Manager 7cxf-rt-rs-json-basicNot affected
Red Hat Integration Camel Quarkus 1cxf-rt-rs-json-basicAffected
Red Hat JBoss Data Virtualization 6cxf-rt-rs-json-basicNot affected
Red Hat JBoss Enterprise Application Platform 6cxf-rt-rs-json-basicNot affected
Red Hat JBoss Enterprise Application Platform 7cxf-rt-rs-json-basicNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packcxf-rt-rs-json-basicNot affected
Red Hat JBoss Fuse 6cxf-rt-rs-json-basicOut of support scope
Red Hat JBoss Fuse Service Works 6cxf-rt-rs-json-basicNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1973392CXF: Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.

CVSS3: 7.5
github
около 4 лет назад

Infinite loop in Apache CFX

7.5 High

CVSS3