CVE-2021-37714
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes.
Published:Aug 18, 2021
Last Modified:Nov 21, 2024
EPS:Aug 18, 2021
EPSS Score:0.00591
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Jsoup
Product
Jsoup
Jsoup
Jsoup
Vendor
Netapp
Product
Management Services For Element Software And Netapp Hci
Netapp
Management Services For Element Software And Netapp Hci
Vendor
Oracle
Product
Banking Trade Finance
Oracle
Banking Trade Finance
Vendor
Oracle
Product
Banking Treasury Management
Oracle
Banking Treasury Management
Vendor
Oracle
Product
Business Process Management Suite
Oracle
Business Process Management Suite
Vendor
Oracle
Product
Communications Messaging Server
Oracle
Communications Messaging Server
Vendor
Oracle
Product
Financial Services Crime And Compliance Management Studio
Oracle
Financial Services Crime And Compliance Management Studio
Vendor
Oracle
Product
Flexcube Universal Banking
Oracle
Flexcube Universal Banking
Vendor
Oracle
Product
Hospitality Token Proxy Service
Oracle
Hospitality Token Proxy Service
Vendor
Oracle
Product
Middleware Common Libraries And Tools
Oracle
Middleware Common Libraries And Tools
Vendor
Oracle
Product
Peoplesoft Enterprise Peopletools
Oracle
Peoplesoft Enterprise Peopletools
Vendor
Oracle
Product
Primavera Unifier
Oracle
Primavera Unifier
Vendor
Oracle
Product
Retail Customer Management And Segmentation Foundation
Oracle
Retail Customer Management And Segmentation Foundation
Vendor
Oracle
Product
Stream Analytics
Oracle
Stream Analytics
Vendor
Oracle
Product
Webcenter Portal
Oracle
Webcenter Portal
Vendor
Quarkus
Product
Quarkus
Quarkus
Quarkus
Vendor
Redhat
Product
Camel Quarkus
Redhat
Camel Quarkus
Vendor
Redhat
Product
Integration
Redhat
Integration
Vendor
Redhat
Product
Jboss Enterprise Application Platform
Redhat
Jboss Enterprise Application Platform
Vendor
Redhat
Product
Jboss Enterprise Application Platform Eus
Redhat
Jboss Enterprise Application Platform Eus
Vendor
Redhat
Product
Jboss Enterprise Bpms Platform
Redhat
Jboss Enterprise Bpms Platform
Vendor
Redhat
Product
Jboss Fuse
Redhat
Jboss Fuse
Vendor
Redhat
Product
Jbosseapxp
Redhat
Jbosseapxp
Vendor
Redhat
Product
Openshift Application Runtimes
Redhat
Openshift Application Runtimes
Vendor
Redhat
Product
Red Hat Single Sign On
Redhat
Red Hat Single Sign On
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
