jackson-dataformat-xml vulnerable to XML external entity (XXE)
RSS Feed
CRITICAL
GHSA-hmq6-frv3-4727
CVE-2016-3720
Description:
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.
Affected Packages
| Ecosystem | Package | Vulnerable Versions | Patched Version |
|---|---|---|---|
| maven |
com.fasterxml.jackson.dataformat:jackson-dataformat-xml
|
< 2.7.4 |
2.7.4
|
Actions
Advisory Details
| Published: | October 18, 2018 almost 8 years ago |
| Updated: | July 29, 2026 about 10 hours ago |
| CVSS Score: | 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS: | 2.78% 85th percentile |
| Source: | Github |
| Classification: | GENERAL |
| UUID: | MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhtcTYtZnJ2My00NzI3 |