CVE-2021-30468: Apache CXF Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.
Other sources
Apache CXF is vulnerable to a denial of service, caused by an infinite loop flaw in the JsonMapObjectReaderWriter function. By sending a specially-crafted JSON to a web service, a remote attacker could exploit this vulnerability to consume available CPU resources.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-30468.
What is the severity of CVE-2021-30468?
The severity of CVE-2021-30468 is high with a severity value of 7.5.
How does CVE-2021-30468 affect Apache CXF?
CVE-2021-30468 affects Apache CXF versions prior to 3.4.4.
What is the impact of CVE-2021-30468?
The impact of CVE-2021-30468 is a denial of service caused by an infinite loop flaw in the JsonMapObjectReaderWriter of Apache CXF.
How can I fix CVE-2021-30468?
To fix CVE-2021-30468, upgrade to Apache CXF version 3.4.4 or later.