Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-37714

Опубликовано: 18 авг. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6jsoupOut of support scope
Red Hat CodeReady Studio 12jsoupWill not fix
Red Hat Enterprise Linux 7jsoupOut of support scope
Red Hat Enterprise Linux 8maven:3.5/jsoupWill not fix
Red Hat Enterprise Linux 8maven:3.6/jsoupWill not fix
Red Hat Enterprise Linux 9jsoupAffected
Red Hat JBoss A-MQ 6jsoupOut of support scope
Red Hat JBoss BRMS 6jsoupOut of support scope
Red Hat JBoss Data Grid 7jsoupOut of support scope
Red Hat JBoss Data Virtualization 6jsoupOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1995259jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck

EPSS

Процентиль: 89%
0.04351
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes.

CVSS3: 7.5
nvd
больше 4 лет назад

jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes.

CVSS3: 7.5
msrc
4 месяца назад

Crafted input may cause the jsoup HTML and XML parser to get stuck, timeout, or throw unchecked exceptions

CVSS3: 7.5
debian
больше 4 лет назад

jsoup is a Java library for working with HTML. Those using jsoup versi ...

suse-cvrf
почти 4 года назад

Security update for jsoup, jsr-305

EPSS

Процентиль: 89%
0.04351
Низкий

7.5 High

CVSS3