CVE-2021-37714

jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
GitHub_MCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
VendorProductVersion
jsoupjsoup
𝑥
< 1.14.2
quarkusquarkus
𝑥
≤ 2.2.3
oraclebanking_trade_finance
14.5
oraclebanking_treasury_management
14.5
oraclebusiness_process_management_suite
12.2.1.3.0
oraclebusiness_process_management_suite
12.2.1.4.0
oracleflexcube_universal_banking
14.0.0 ≤
𝑥
≤ 14.3.0
oracleflexcube_universal_banking
14.5
oraclehospitality_token_proxy_service
19.2
oraclepeoplesoft_enterprise_peopletools
8.58
oraclepeoplesoft_enterprise_peopletools
8.59
oracleprimavera_unifier
20.12
oracleprimavera_unifier
21.12
oracleretail_customer_management_and_segmentation_foundation
17.0 ≤
𝑥
≤ 19.0
oraclewebcenter_portal
12.2.1.3.0
oraclewebcenter_portal
12.2.1.4.0
oraclecommunications_messaging_server
8.1
netappmanagement_services_for_element_software_and_netapp_hci
-
oraclefinancial_services_crime_and_compliance_management_studio
8.0.8.2.0
oraclefinancial_services_crime_and_compliance_management_studio
8.0.8.3.0
oraclemiddleware_common_libraries_and_tools
12.2.1.3.0
oraclemiddleware_common_libraries_and_tools
12.2.1.4.0
oraclestream_analytics
𝑥
< 19.1.0.0.6.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jsoup
bullseye
no-dsa
buster
no-dsa
stretch
no-dsa
sid
1.15.3-1
fixed
trixie
1.15.3-1
fixed
bookworm
1.15.3-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jsoup
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
ignored
jammy
needs-triage
impish
ignored
hirsute
ignored
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
needs-triage
References