Description
Issue:
This vulnerability is caused by JsonMapObjectReaderWriter.class of cxf-rt-rs-json-basic.jar. When a malformed JSON is submitted to a web service, it results in thread getting stuck in an infinite loop, consuming CPU indefinitely.
This is resolved from Apache CXF 3.3.11 or later.