QID 981038
QID 981038: Java (maven) Security Update for com.fasterxml.jackson.dataformat:jackson-dataformat-xml (GHSA-hmq6-frv3-4727)
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hmq6-frv3-4727 for updates pertaining to this vulnerability.
Vendor References
- GHSA-hmq6-frv3-4727 -
github.com/advisories/GHSA-hmq6-frv3-4727
CVEs related to QID 981038
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hmq6-frv3-4727 | com.fasterxml.jackson.dataformat:jackson-dataformat-xml |
|