Bugzilla – Bug 1187446
VUL-0: CVE-2021-33813: jdom,jdom2: XXE issue in SAXBuilder can cause a denial of service via a crafted HTTP request
Last modified: 2024-06-10 12:07:53 UTC
CVE-2021-33813 An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. Open PR: https://github.com/hunterhacker/jdom/pull/188 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-33813 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33813 https://github.com/hunterhacker/jdom/pull/188 https://github.com/hunterhacker/jdom/releases https://alephsecurity.com/vulns/aleph-2021003
See also: https://github.com/hunterhacker/jdom/issues/189
Upstream merge commit has been accepted. Submitted to Factory here: https://build.opensuse.org/request/show/903069
openSUSE-SU-2021:2293-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1187446 CVE References: CVE-2021-33813 JIRA References: Sources used: openSUSE Leap 15.3 (src): jdom2-2.0.6-3.3.1
SUSE-SU-2021:2293-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1187446 CVE References: CVE-2021-33813 JIRA References: Sources used: SUSE Linux Enterprise Module for Development Tools 15-SP3 (src): jdom2-2.0.6-3.3.1 SUSE Linux Enterprise Module for Development Tools 15-SP2 (src): jdom2-2.0.6-3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:1031-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1187446 CVE References: CVE-2021-33813 JIRA References: Sources used: openSUSE Leap 15.2 (src): jdom2-2.0.6-lp152.2.3.1
All done and sent back to security team to review.
SUSE-SU-2022:3547-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1187446 CVE References: CVE-2021-33813 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15-SP1 (src): jdom-1.1-150000.5.3.1 SUSE Linux Enterprise Server for SAP 15 (src): jdom-1.1-150000.5.3.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): jdom-1.1-150000.5.3.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): jdom-1.1-150000.5.3.1 SUSE Linux Enterprise Server 15-LTSS (src): jdom-1.1-150000.5.3.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): jdom-1.1-150000.5.3.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): jdom-1.1-150000.5.3.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): jdom-1.1-150000.5.3.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): jdom-1.1-150000.5.3.1 SUSE Enterprise Storage 6 (src): jdom-1.1-150000.5.3.1 SUSE CaaS Platform 4.0 (src): jdom-1.1-150000.5.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2024:1874-1: An update that solves one vulnerability and has one security fix can now be installed. Category: security (important) Bug References: 1187446, 1224410 CVE References: CVE-2021-33813 Maintenance Incident: [SUSE:Maintenance:34072](https://smelt.suse.de/incident/34072/) Sources used: openSUSE Leap 15.5 (src): apiguardian-1.1.2-150200.3.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, open-test-reporting-0.1.0~M2-150200.5.7.2, assertj-core-3.25.3-150200.5.4.3, junit5-minimal-5.10.2-150200.3.10.2, junit-4.13.2-150200.3.15.2, byte-buddy-1.14.16-150200.5.7.1, jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, saxpath-1.0-150200.5.3.3, junit5-5.10.2-150200.3.10.3, jopt-simple-5.0.4-150200.3.4.3, xom-1.3.9-150200.5.3.3 openSUSE Leap 15.6 (src): apiguardian-1.1.2-150200.3.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, open-test-reporting-0.1.0~M2-150200.5.7.2, assertj-core-3.25.3-150200.5.4.3, junit5-minimal-5.10.2-150200.3.10.2, junit-4.13.2-150200.3.15.2, byte-buddy-1.14.16-150200.5.7.1, jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, saxpath-1.0-150200.5.3.3, junit5-5.10.2-150200.3.10.3, jopt-simple-5.0.4-150200.3.4.3, xom-1.3.9-150200.5.3.3 Basesystem Module 15-SP5 (src): objectweb-asm-9.7-150200.3.15.2 Basesystem Module 15-SP6 (src): objectweb-asm-9.7-150200.3.15.2 Development Tools Module 15-SP5 (src): jdom-1.1.3-150200.12.8.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 Development Tools Module 15-SP6 (src): jdom-1.1.3-150200.12.8.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 SUSE Package Hub 15 15-SP6 (src): apiguardian-1.1.2-150200.3.10.2, open-test-reporting-0.1.0~M2-150200.5.7.2, assertj-core-3.25.3-150200.5.4.3, junit5-5.10.2-150200.3.10.3, jopt-simple-5.0.4-150200.3.4.3, junit5-minimal-5.10.2-150200.3.10.2, byte-buddy-1.14.16-150200.5.7.1 SUSE Manager Server 4.3 Module 4.3 (src): jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, xom-1.3.9-150200.5.3.3 SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src): jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src): jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (src): jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src): jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src): jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (src): jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src): jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src): jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 SUSE Linux Enterprise Server for SAP Applications 15 SP4 (src): jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 SUSE Manager Proxy 4.3 (src): objectweb-asm-9.7-150200.3.15.2 SUSE Manager Retail Branch Server 4.3 (src): objectweb-asm-9.7-150200.3.15.2 SUSE Manager Server 4.3 (src): objectweb-asm-9.7-150200.3.15.2 SUSE Enterprise Storage 7.1 (src): jdom-1.1.3-150200.12.8.2, objectweb-asm-9.7-150200.3.15.2, dom4j-2.1.4-150200.12.10.2, jaxen-2.0.0-150200.5.3.1, hamcrest-2.2-150200.12.17.2, junit-4.13.2-150200.3.15.2, xom-1.3.9-150200.5.3.3 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
All done, closing.