CVE-2021-46877
Published on: Not Yet Published
Last Modified on: 03/18/2023 10:15:00 PM UTC
The following vulnerability was found:
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
- CVE-2021-46877 has been assigned by
[email protected] to track the vulnerability
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Possible DoS if using JDK serialization to serialize `JsonNode` · Issue #3328 · FasterXML/jackson-databind · GitHub | github.com text/html |
![]() |
Jackson 2.12.6 and 2.13.1 patch releases: one CVE fix | groups.google.com text/html |
![]() |
There are currently no QIDs associated with this CVE
There are no known software configurations (CPEs) currently associated with this CVE
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-46877 : jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to… twitter.com/i/web/status/1… | 2023-03-18 22:08:22 |
![]() |
CVE-2021-46877 | 2023-03-18 23:38:22 |