CVE-2021-46877: High severity fasterxml jackson-databind vulnerability
A flaw was found in Jackson Databind. This issue may allow a malicious user to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
Other sources
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.401.1.1686649641-3.el8 - Upgrade
Upgrade
redhat/jenkinsto a version that resolves this vulnerability.Fixed in 0:2.387.3.1684911776-3.el8 - Upgrade
Upgrade
redhat/eap7-wildflyto a version that resolves this vulnerability.Fixed in 0:7.4.12-3.GA_redhat_00003.1.el8ea - Upgrade
Upgrade
redhat/eap7-wildflyto a version that resolves this vulnerability.Fixed in 0:7.4.12-3.GA_redhat_00003.1.el9ea - Upgrade
Upgrade
redhat/eap7-wildflyto a version that resolves this vulnerability.Fixed in 0:7.4.12-3.GA_redhat_00003.1.el7ea - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.9-1.redhat_00001.1.el7 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.9-1.redhat_00001.1.el8 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.9-1.redhat_00001.1.el9 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.13.1 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.12.6 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.13.1 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.12.6
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-46877?
The severity of CVE-2021-46877 is high with a severity value of 7.5.
What is the affected software of CVE-2021-46877?
The affected software of CVE-2021-46877 includes jackson-databind versions 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1.
How can an attacker exploit CVE-2021-46877?
An attacker can exploit CVE-2021-46877 to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
What is the remedy for CVE-2021-46877?
The remedy for CVE-2021-46877 is to update to jackson-databind version 2.12.6 or 2.13.1.
Where can I find more information about CVE-2021-46877?
You can find more information about CVE-2021-46877 on the CVE website (https://www.cve.org/CVERecord?id=CVE-2021-46877) and the NIST National Vulnerability Database (https://nvd.nist.gov/vuln/detail/CVE-2021-46877).