CVE-2021-22569 is a medium-severity vulnerability affecting Google and Oracle products utilizing protobuf-java, where a malicious payload can cause a denial of service by forcing the parser to process interleaved UnknownFieldSet fields out of order, leading to frequent pauses. The attack requires local access and user interaction, but can result in high availability impact. There is no public exploit code available, nor is it known to be actively exploited, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.19.2CPE matchmatch criteria | cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:* | ||
< 3.16.1CPE matchmatch criteria | cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:* | ||
>= 3.18.0, < 3.18.2CPE matchmatch criteria | cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:* | ||
>= 3.19.0, < 3.19.2CPE matchmatch criteria | cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:* | ||
< 3.18.2CPE matchmatch criteria | cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2021-22569
Sep 10, 2024Denial of Service of protobuf-java parsing procedure
Jan 11, 2022A potential Denial of Service issue in protobuf-java
Jan 7, 2022protobuf-java: potential DoS in the parsing procedure for binary data
Jan 6, 2022Denial of Service in protobuf-java (CVE-2021-22569)
Denial of Service in protobuf-java (CVE-2021-22569)