CVE-2021-46877
published 2023-03-18CVE-2021-46877: jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.12%
62.6th percentile
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | jira_software | — | — |
| debian | jackson-databind | < jackson-databind 2.13.2.2-1 (bookworm) | jackson-databind 2.13.2.2-1 (bookworm) |
| fasterxml | jackson-databind | — | — |
| fasterxml | jackson-databind | >= 0 < 2.13.2.2-1 | 2.13.2.2-1 |
| fasterxml | jackson-databind | >= 0 < 2.13.2.2-1 | 2.13.2.2-1 |
| fasterxml | jackson-databind | >= 0 < 2.13.2.2-1 | 2.13.2.2-1 |
| fasterxml | jackson-databind | >= 2.10.0 < 2.12.6 | 2.12.6 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_oracle6.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Atlassian
CVE-2021-46877: DoS (Denial of Service) jackson-databind in Jira Software Data Center and Server
vendor_atlassian·2023-11-21·CVSS 7.5
CVE-2021-46877 [HIGH] CVE-2021-46877: DoS (Denial of Service) jackson-databind in Jira Software Data Center and Server
CVE-2021-46877: DoS (Denial of Service) jackson-databind in Jira Software Data Center and Server
DoS (Denial of Service) jackson-databind in Jira Software Data Center and Server
CVE: CVE-2021-46877
Severity: HIGH
Affected products: Jira Software
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: 10g - Users, roles, credentials, security (jackson-databind) — CVE-2021-46877
vendor_oracle·2023-07-15·CVSS 6.5
CVE-2021-46877 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: 10g - Users, roles, credentials, security (jackson-databind) — CVE-2021-46877
Oracle Oracle Fusion Middleware Risk Matrix: 10g - Users, roles, credentials, security (jackson-databind) vulnerability
CVE: CVE-2021-46877
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Red Hat
jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode
vendor_redhat·2023-03-19·CVSS 7.5
CVE-2021-46877 [HIGH] CWE-400 jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode
jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
A flaw was found in Jackson Databind. This issue may allow a malicious user to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
Package: jackson-databind (A-MQ Clients 2) - Not affected
Package: jackson-databind (Cryostat 2) - Will not fix
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: jenkins-2-plugins (OpenShift Developer Tools and Services) - No
Debian
CVE-2021-46877: jackson-databind - jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 al...
vendor_debian·2021·CVSS 7.5
CVE-2021-46877 [HIGH] CVE-2021-46877: jackson-databind - jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 al...
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
Scope: local
bookworm: resolved (fixed in 2.13.2.2-1)
bullseye: open
forky: resolved (fixed in 2.13.2.2-1)
sid: resolved (fixed in 2.13.2.2-1)
trixie: resolved (fixed in 2.13.2.2-1)
OSV
jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
osv·2023-03-19
CVE-2021-46877 [HIGH] jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
GHSA
jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
ghsa·2023-03-19
CVE-2021-46877 [HIGH] CWE-770 jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
OSV
CVE-2021-46877: jackson-databind 2
osv·2023-03-18·CVSS 7.5
CVE-2021-46877 [HIGH] CVE-2021-46877: jackson-databind 2
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-18
Published