Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-10172

Опубликовано: 18 нояб. 2019
Источник: debian

Описание

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libjackson-json-javafixed1.9.13-2package
libjackson-json-javafixed1.9.13-2~deb10u1busterpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1715075

  • https://stackoverflow.com/questions/38017676/small-fix-for-cve-2016-3720-with-older-versions-of-jackson-all-1-9-11-and-in-ja/38017721

  • https://github.com/FasterXML/jackson-1/pull/1

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

CVSS3: 5.9
redhat
около 6 лет назад

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

CVSS3: 7.5
nvd
около 6 лет назад

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

CVSS3: 7.5
github
около 6 лет назад

Improper Restriction of XML External Entity Reference in jackson-mapper-asl

CVSS3: 5.9
fstec
около 6 лет назад

Уязвимость компонента org.codehaus.jackson библиотеки jackson-mapper-asl, позволяющая нарушителю оказать воздействие на целостность данных