CVE-2021-46877
CVSS V2 None
CVSS V3 None
Description
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
Overview
- CVE ID
- CVE-2021-46877
- Assigner
- cve@mitre.org
- Vulnerability Status
- Analyzed
- Published Version
- 2023-03-18T22:15:11
- Last Modified Date
- 2023-03-23T14:04:35
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:fastxml:jackson-databind:*:*:*:*:*:*:*:* | 1 | OR | 2.10.0 | 2.12.6 |
cpe:2.3:a:fastxml:jackson-databind:2.13.0:-:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:a:fastxml:jackson-databind:2.13.0:rc1:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:a:fastxml:jackson-databind:2.13.0:rc2:*:*:*:*:*:* | 1 | OR |
References
Reference URL | Reference Tags |
---|---|
https://github.com/FasterXML/jackson-databind/issues/3328 | Exploit Issue Tracking Vendor Advisory |
https://groups.google.com/g/jackson-user/c/OsBsirPM_Vw | Mailing List Release Notes |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2021-46877 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46877 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 02:56:53 | Added to TrackCVE | |||
2023-04-17 02:56:54 | Weakness Enumeration | new |