cbcvebase.
CVE-2021-31812
published 2021-06-12

CVE-2021-31812: In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior…

PriorityP426medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
3.05%
86.1th percentile
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.

Affected

18 ranges
VendorProductVersion rangeFixed in
apachepdfbox2.0.0 – 2.0.23
apachetika
apache_software_foundationapache_pdfbox>= Apache PDFBox < 2.0.242.0.24
debianlibpdfbox-java< libpdfbox2-java 2.0.24-1 (bookworm)libpdfbox2-java 2.0.24-1 (bookworm)
debianlibpdfbox2-java< libpdfbox2-java 2.0.24-1 (bookworm)libpdfbox2-java 2.0.24-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
oraclebanking_corporate_lending_process_management
oraclebanking_corporate_lending_process_management
oraclebanking_corporate_lending_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_supply_chain_finance
oraclebanking_supply_chain_finance
oraclebanking_supply_chain_finance
oraclecommunications_messaging_server
oracleretail_customer_management_and_segmentation_foundation

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_apache5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.