CVE-2021-22569

An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:*
cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*
cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*
cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*
cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:*
cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:spatial_and_graph_mapviewer:19c:*:*:*:*:*:*:*
cpe:2.3:a:oracle:spatial_and_graph_mapviewer:21c:*:*:*:*:*:*:*

History

18 Apr 2023, 09:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/04/msg00019.html -

10 May 2022, 18:03

Type Values Removed Values Added
First Time Oracle
Oracle communications Cloud Native Core Network Repository Function
Oracle spatial And Graph Mapviewer
Oracle communications Cloud Native Core Console
Oracle communications Cloud Native Core Policy
CPE cpe:2.3:a:oracle:spatial_and_graph_mapviewer:21c:*:*:*:*:*:*:*
cpe:2.3:a:oracle:spatial_and_graph_mapviewer:19c:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*
References (MISC) https://www.oracle.com/security-alerts/cpuapr2022.html - (MISC) https://www.oracle.com/security-alerts/cpuapr2022.html - Patch, Third Party Advisory

20 Apr 2022, 00:15

Type Values Removed Values Added
References
  • (MISC) https://www.oracle.com/security-alerts/cpuapr2022.html -

14 Jan 2022, 15:41

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.5
CPE cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*
cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:*
cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:*
References (MISC) https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=39330 - (MISC) https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=39330 - Exploit, Issue Tracking, Mailing List, Vendor Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/01/12/4 - (MLIST) http://www.openwall.com/lists/oss-security/2022/01/12/4 - Mailing List, Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/01/12/7 - (MLIST) http://www.openwall.com/lists/oss-security/2022/01/12/7 - Mailing List, Third Party Advisory
References (MISC) https://cloud.google.com/support/bulletins#gcp-2022-001 - (MISC) https://cloud.google.com/support/bulletins#gcp-2022-001 - Vendor Advisory
First Time Google google-protobuf
Google
Google protobuf-kotlin
Google protobuf-java

13 Jan 2022, 01:15

Type Values Removed Values Added
References
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/01/12/7 -

12 Jan 2022, 16:15

Type Values Removed Values Added
References
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/01/12/4 -

10 Jan 2022, 14:14

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-10 14:10

Updated : 2023-12-10 14:09


NVD link : CVE-2021-22569

Mitre link : CVE-2021-22569

CVE.ORG link : CVE-2021-22569


JSON object : View

Products Affected

oracle

  • spatial_and_graph_mapviewer
  • communications_cloud_native_core_policy
  • communications_cloud_native_core_network_repository_function
  • communications_cloud_native_core_console

google

  • google-protobuf
  • protobuf-kotlin
  • protobuf-java
CWE
NVD-CWE-noinfo CWE-696

Incorrect Behavior Order