CVE-2021-37714 Details
Description
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | [email protected] |
| CWE-248 | Uncaught Exception | [email protected] |
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| jsoup jsoup | < 1.14.2 |
CPE
Remediation
| |
| quarkus quarkus | <= 2.2.3 |
CPE
Remediation
| |
| oracle banking trade finance | 14.5 |
CPE
Remediation
| |
| oracle banking treasury management | 14.5 |
CPE
Remediation
| |
| oracle business process management suite | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle flexcube universal banking | >= 14.0.0, <= 14.3.0 14.5 |
CPE
Remediation
| |
| oracle hospitality token proxy service | 19.2 |
CPE
Remediation
| |
| oracle peoplesoft enterprise peopletools | 8.58 8.59 |
CPE
Remediation
| |
| oracle primavera unifier | 20.12 21.12 |
CPE
Remediation
| |
| oracle retail customer management and segmentation foundation | >= 17.0, <= 19.0 |
CPE
Remediation
| |
| oracle webcenter portal | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle communications messaging server | 8.1 |
CPE
Remediation
| |
| netapp management services for element software and netapp hci | All versions |
CPE
Remediation
| |
| oracle financial services crime and compliance management studio | 8.0.8.2.0 8.0.8.3.0 |
CPE
Remediation
| |
| oracle middleware common libraries and tools | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle stream analytics | < 19.1.0.0.6.4 19c |
CPE
Remediation
| |
Change History
19 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Dec 7, 2022 | Modified Analysis | [email protected] |
| Jul 25, 2022 | CVE Modified | [email protected] |
| May 10, 2022 | Modified Analysis | [email protected] |
| Apr 20, 2022 | CVE Modified | [email protected] |
| Mar 4, 2022 | Modified Analysis | [email protected] |
| Feb 10, 2022 | CVE Modified | [email protected] |
| Feb 7, 2022 | CVE Modified | [email protected] |
| Oct 20, 2021 | Reanalysis | [email protected] |
| Oct 18, 2021 | Modified Analysis | [email protected] |
| Sep 1, 2021 | CVE Modified | [email protected] |
| Sep 1, 2021 | CVE Modified | [email protected] |
| Aug 30, 2021 | CVE Modified | [email protected] |
| Aug 26, 2021 | Initial Analysis | [email protected] |
| Aug 24, 2021 | CVE Modified | [email protected] |
| Aug 20, 2021 | CVE Modified | [email protected] |