漏洞信息详情
Apache CXF 资源管理错误漏洞
漏洞简介
Apache CXF是美国阿帕奇(Apache)基金会的一个开源的Web服务框架。该框架支持多种Web服务标准、多种前端编程API等。
Apache CXF存在资源管理错误漏洞,该漏洞源于Apache CXF的JsonMapObjectReaderWriter中的一个漏洞允许攻击者可利用该漏洞向web服务提交畸形的JSON,这将导致线程陷入无限循环,无限期地消耗CPU。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://lists.apache.org/thread.html/r4a4b6bc0520b69c18d2a59daa6af84ae49f0c22164dccb8538794459@%3Cannounce.apache.org%3E
参考网址
来源:MLIST
链接:https://lists.apache.org/thread.html/r4a4b6bc0520b69c18d2a59daa6af84ae49f0c22164dccb8538794459@%3Cdev.cxf.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/re9e05c6cab5f0dcc827eba4e6fcf26fa0b493e7ca84d62c867a80d03@%3Ccommits.tomee.apache.org%3E
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210917-0002/
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2021/06/16/2
来源:MLIST
链接:https://lists.apache.org/thread.html/r4a4b6bc0520b69c18d2a59daa6af84ae49f0c22164dccb8538794459@%3Cannounce.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/re5b2a2b77faa22684d47bd2ac6623135c615565328ff40a1ec705448@%3Ccommits.tomee.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r3f46ae38e4a6e80c069cdb320e0ce831b0a21a12ef0cc92c0943f34a@%3Ccommits.tomee.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/rac07822057521dccf33ab5d136e0e8c599a6e2c8ac75e44ffbdc6e07@%3Ccommits.tomee.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r4771084730c4cf6e59eda60b4407122c86f174eb750b24f610ba9ff4@%3Ccommits.tomee.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r4a4b6bc0520b69c18d2a59daa6af84ae49f0c22164dccb8538794459@%3Cusers.cxf.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r54c0f1cbbb9f381dfbedb9ea5e90ecb1c0a15371f40c4b10322ac737@%3Ccommits.tomee.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/ra833f78b3fa577cb43558cf343859a1bf70b1c5ce2353b3877d96422@%3Ccommits.tomee.apache.org%3E
来源:CONFIRM
链接:http://cxf.apache.org/security-advisories.data/CVE-2021-30468.txt.asc
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuoct2021.html
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Oracle-Communications-vulnerabilities-of-October-2021-36675
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163872/Red-Hat-Security-Advisory-2021-3205-01.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021101933
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpuoct2021.html
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6483303
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6520492
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2816
受影响实体
暂无
补丁
- Apache CXF 资源管理错误漏洞的修复措施<!--2021-6-16-->
还没有评论,来说两句吧...