CVE-2021-46877
A flaw was found in Jackson Databind. This issue may allow a malicious user to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-46877?
The severity of CVE-2021-46877 is high with a severity value of 7.5.
What is the affected software of CVE-2021-46877?
The affected software of CVE-2021-46877 includes jackson-databind versions 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1.
How can an attacker exploit CVE-2021-46877?
An attacker can exploit CVE-2021-46877 to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
What is the remedy for CVE-2021-46877?
The remedy for CVE-2021-46877 is to update to jackson-databind version 2.12.6 or 2.13.1.
Where can I find more information about CVE-2021-46877?
You can find more information about CVE-2021-46877 on the CVE website (https://www.cve.org/CVERecord?id=CVE-2021-46877) and the NIST National Vulnerability Database (https://nvd.nist.gov/vuln/detail/CVE-2021-46877).