A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cxf | Apache | * | 3.3.11 (excluding) |
Cxf | Apache | 3.4.0 (including) | 3.4.4 (excluding) |
Tomee | Apache | 8.0.6 (including) | 8.0.6 (including) |
JWS 5.7.0 | RedHat | cxf-rt-rs-json-basic | * |
Red Hat Fuse 7.10 | RedHat | cxf-rt-rs-json-basic | * |
Red Hat Integration | RedHat | cxf-rt-rs-json-basic | * |