CVE-2021-33813
Summary
| CVE | CVE-2021-33813 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-16 12:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 35 Update: jdom2-2.0.6-24.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: jdom-1.1.3-27.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| [solr-issues] 20210813 [jira] [Commented] (SOLR-15529) High security vulnerability in JDOM library bundled within Solr 8.9 CVE-2021-33813 |
|
lists.apache.org |
|
| [SECURITY] [DLA 2712-1] libjdom1-java security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 35 Update: jdom-1.1.3-27.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Releases · hunterhacker/jdom · GitHub |
MISC |
github.com |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| [solr-issues] 20210819 [jira] [Resolved] (SOLR-15529) High security vulnerability in JDOM library bundled within Solr 8.9 CVE-2021-33813 |
|
lists.apache.org |
|
| fix setFeature bug and add test case by esti-burstein · Pull Request #188 · hunterhacker/jdom · GitHub |
MISC |
github.com |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| [solr-issues] 20210813 [jira] [Updated] (SOLR-15529) High security vulnerability in JDOM library bundled within Solr 8.9 CVE-2021-33813 |
|
lists.apache.org |
|
| [SECURITY] Fedora 35 Update: jdom2-2.0.6-24.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [solr-issues] 20210711 [jira] [Created] (SOLR-15530) High security vulnerability in jackson-databind bundled within Solr 8.9 |
|
lists.apache.org |
|
| [solr-issues] 20210711 [jira] [Updated] (SOLR-15529) High security vulnerability in JDOM library bundled within Solr 8.9 CVE-2021-33813 |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| [SECURITY] [DLA 2696-1] libjdom2-java security update |
MLIST |
lists.debian.org |
|
| [CVE-2021-33813] XXE in JDOM library - Java |
MISC |
alephsecurity.com |
|
| [tika-dev] 20210721 [jira] [Created] (TIKA-3488) Security issue XXE in TIKA due to JDOM |
|
lists.apache.org |
|
| [solr-issues] 20210711 [jira] [Created] (SOLR-15529) High security vulnerability in JDOM library bundled within Solr 8.9 CVE-2021-33813 |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| [solr-issues] 20210819 [jira] [Commented] (SOLR-15529) High security vulnerability in JDOM library bundled within Solr 8.9 CVE-2021-33813 |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178688 Debian Security Update for libjdom2-java (DLA 2696-1)
- 178717 Debian Security Update for libjdom1-java (DLA 2712-1)
- 180166 Debian Security Update for libjdom2-javalibjdom1-java (CVE-2021-33813)
- 354386 Amazon Linux Security Advisory for jdom : ALAS2022-2022-168
- 354506 Amazon Linux Security Advisory for jdom : ALAS2022-2022-010
- 355085 Amazon Linux Security Advisory for jdom : ALAS2-2023-2045
- 355204 Amazon Linux Security Advisory for jdom : ALAS2023-2023-014
- 671859 EulerOS Security Update for jdom (EulerOS-SA-2022-1895)
- 671867 EulerOS Security Update for jdom (EulerOS-SA-2022-1933)
- 672247 EulerOS Security Update for jdom (EulerOS-SA-2022-2618)
- 750754 OpenSUSE Security Update for jdom2 (openSUSE-SU-2021:2293-1)
- 750829 OpenSUSE Security Update for jdom2 (openSUSE-SU-2021:1031-1)
- 752716 SUSE Enterprise Linux Security Update for jdom (SUSE-SU-2022:3547-1)
- 980240 Java (maven) Security Update for org.jdom:jdom (GHSA-2363-cqg2-863c)