
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-30468 is a vulnerability discovered in the JsonMapObjectReaderWriter component of Apache CXF. The vulnerability allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This vulnerability affects Apache CXF versions prior to 3.4.4 and versions prior to 3.3.11. The vulnerability was disclosed in June 2021 (NVD, Apache Advisory).
The vulnerability is classified as an Uncontrolled Resource Consumption (CWE-400) and Loop with Unreachable Exit Condition (CWE-835) issue. It has received a CVSS v3.1 base score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating it is network-accessible, requires low attack complexity, and primarily impacts system availability (NVD).
When successfully exploited, the vulnerability leads to a Denial of Service (DoS) condition by causing the affected thread to enter an infinite loop, which results in continuous CPU consumption. This can significantly impact system availability and performance (NetApp Advisory).
The primary mitigation is to upgrade to Apache CXF version 3.4.4 or later for the 3.4.x series, or version 3.3.11 or later for the 3.3.x series. The vulnerability has been addressed in these versions (Apache Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."