CVE-2021-30468
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.
Date published : 2021-06-16
https://security.netapp.com/advisory/ntap-20210917-0002/
http://cxf.apache.org/security-advisories.data/CVE-2021-30468.txt.asc