PT-2021-7982 · Atlassian+1 · Bamboo Data Center/Server+6

CVE-2021-46877

·

Published

2021-12-20

·

Updated

2026-08-31

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions jackson-databind versions 2.10.x through 2.12.x before 2.12.6 jackson-databind versions 2.13.x before 2.13.1 Bitbucket Data Center and Server versions 7.17.0, 7.21.0, 8.7.0, 8.8.0, 8.9.0, 8.10.0, 8.11.0, 8.12.0, and 8.13.0 Bamboo Data Center and Server versions 9.1.0, 9.2.1, and 9.3.0
Description The issue is related to unlimited resource allocation in the jackson-databind library, which can be exploited by a remote attacker to cause a denial of service. This can result in 2 GB transient heap usage per read in uncommon situations involving JsonNode JDK serialization. The vulnerability has no impact on confidentiality and integrity but has a high impact on availability and requires no user interaction.
Recommendations For jackson-databind versions 2.10.x through 2.12.x before 2.12.6, upgrade to version 2.12.6 or later. For jackson-databind versions 2.13.x before 2.13.1, upgrade to version 2.13.1 or later. For Bitbucket Data Center and Server version 7.21, upgrade to a release greater than or equal to 7.21.14. For Bitbucket Data Center and Server version 8.9, upgrade to a release greater than or equal to 8.9.4. For Bitbucket Data Center and Server version 8.10, upgrade to a release greater than or equal to 8.10.4. For Bitbucket Data Center and Server version 8.11, upgrade to a release greater than or equal to 8.11.3. For Bitbucket Data Center and Server version 8.12, upgrade to a release greater than or equal to 8.12.1. For Bitbucket Data Center and Server version 8.13, upgrade to a release greater than or equal to 8.13.1. For Bamboo Data Center and Server version 9.2, upgrade to a release greater than or equal to 9.2.5. For Bamboo Data Center and Server version 9.3, upgrade to a release greater than or equal to 9.3.3.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00088
CVE-2021-46877
GHSA-3X8X-79M2-3W2W
RHSA-2023:2097
RHSA-2023:3299
RHSA-2023:3610
RHSA-2023:4505
RHSA-2023:4506
RHSA-2023:4507
RHSA-2023:4918
RHSA-2023:4919
RHSA-2023:4920

Affected Products

Bamboo
Bamboo Data Center/Server
Bitbucket
Bitbucket Data Center/Server
Debian
Jira
Jira Service Management Server