CVE Vulnerabilities

CVE-2021-30468

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jun 16, 2021 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu

A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Cxf Apache * 3.3.11 (excluding)
Cxf Apache 3.4.0 (including) 3.4.4 (excluding)
Tomee Apache 8.0.6 (including) 8.0.6 (including)
JWS 5.7.0 RedHat cxf-rt-rs-json-basic *
Red Hat Fuse 7.10 RedHat cxf-rt-rs-json-basic *
Red Hat Integration RedHat cxf-rt-rs-json-basic *

References