7.5
CVE-2021-37714
- EPSS 6.87%
- Veröffentlicht 18.08.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:46
- Erkennungen
Crafted input may cause the jsoup HTML and XML parser to get stuck, timeout, or throw unchecked exceptions
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Banking Trade Finance Version 14.5
Oracle ≫ Banking Treasury Management Version 14.5
Oracle ≫ Business Process Management Suite Version 12.2.1.3.0
Oracle ≫ Business Process Management Suite Version 12.2.1.4.0
Oracle ≫ Flexcube Universal Banking Version >= 14.0.0 <= 14.3.0
Oracle ≫ Flexcube Universal Banking Version 14.5
Oracle ≫ Hospitality Token Proxy Service Version 19.2
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.58
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.59
Oracle ≫ Primavera Unifier Version 20.12
Oracle ≫ Primavera Unifier Version 21.12
Oracle ≫ Retail Customer Management And Segmentation Foundation Version >= 17.0 <= 19.0
Oracle ≫ Webcenter Portal Version 12.2.1.3.0
Oracle ≫ Webcenter Portal Version 12.2.1.4.0
Oracle ≫ Communications Messaging Server Version 8.1
Oracle ≫ Financial Services Crime And Compliance Management Studio Version 8.0.8.2.0
Oracle ≫ Financial Services Crime And Compliance Management Studio Version 8.0.8.3.0
Oracle ≫ Middleware Common Libraries And Tools Version 12.2.1.3.0
Oracle ≫ Middleware Common Libraries And Tools Version 12.2.1.4.0
Oracle ≫ Stream Analytics Version < 19.1.0.0.6.4
Oracle ≫ Stream Analytics Version 19c
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.87% | 0.932 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-248 Uncaught Exception
An exception is thrown from a function, but it is not caught.
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://github.com/jhy/jsoup/security/advisories/GHSA-m72m-mhq2-9p6c
https://jsoup.org/news/release-1.14.1
https://jsoup.org/news/release-1.14.2
https://lists.apache.org/thread.html/r215009dbf7467a9f6506d0c0024cb36cad30071010e62c9352cfaaf0%40%3Cissues.maven.apache.org%3E
https://lists.apache.org/thread.html/r377b93d79817ce649e9e68b3456e6f499747ef1643fa987b342e082e%40%3Cissues.maven.apache.org%3E
https://lists.apache.org/thread.html/r3d71f18adb78e50f626dde689161ca63d3b7491bd9718fcddfaecba7%40%3Cissues.maven.apache.org%3E
https://lists.apache.org/thread.html/r50e9c9466c592ca9d707a5dea549524d19e3287da08d8392f643960e%40%3Cissues.maven.apache.org%3E
https://lists.apache.org/thread.html/r685c5235235ad0c26e86d0ee987fb802c9675de6081dbf0516464e0b%40%3Cnotifications.james.apache.org%3E
https://lists.apache.org/thread.html/r97404676a5cf591988faedb887d64e278f522adcaa823d89ca69defe%40%3Cnotifications.james.apache.org%3E
https://lists.apache.org/thread.html/rc3354080fc67fb50b45b3c2d12dc4ca2a3c1c78dad3d3ba012c038aa%40%3Cnotifications.james.apache.org%3E
https://security.netapp.com/advisory/ntap-20220210-0022/