Files
CVEs-PoC/2021/CVE-2021-46877.md
2025-09-29 21:09:30 +02:00

21 lines
840 B
Markdown

### [CVE-2021-46877](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46877)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen)
### Description
jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/Meleksebri/tp4_image
- https://github.com/ayleeee/Security-Analysis-Using-Trivy
- https://github.com/scordero1234/java_sec_demo-main
- https://github.com/seal-community/patches