Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10172

Опубликовано: 18 нояб. 2019
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries such that an XML external entity (XXE) vulnerability affects codehaus's jackson-mapper-asl libraries. This vulnerability is similar to CVE-2016-3720. The primary threat from this flaw is data integrity.

Отчет

Red Hat OpenStack Platform ships OpenDaylight, which contains the vulnerable jackson-databind. However, OpenDaylight does not expose jackson-databind in a way that would make it vulnerable, lowering the impact of the vulnerability for OpenDaylight. As such, Red Hat will not be providing a fix for OpenDaylight at this time.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6jackson-mapper-aslOut of support scope
Red Hat Decision Manager 7jackson-mapper-aslWill not fix
Red Hat JBoss A-MQ 6jackson-mapper-aslOut of support scope
Red Hat JBoss BRMS 5jackson-mapper-aslOut of support scope
Red Hat JBoss Data Virtualization 6jackson-mapper-aslOut of support scope
Red Hat JBoss Enterprise Application Platform 5jackson-mapper-aslOut of support scope
Red Hat JBoss Enterprise Application Platform 6jackson-mapper-aslOut of support scope
Red Hat JBoss Fuse 6jackson-mapper-aslOut of support scope
Red Hat JBoss Fuse Service Works 6jackson-mapper-aslOut of support scope
Red Hat JBoss Operations Network 3jackson-mapper-aslOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1715075jackson-mapper-asl: XML external entity similar to CVE-2016-3720

EPSS

Процентиль: 68%
0.00563
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

CVSS3: 7.5
nvd
около 6 лет назад

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

CVSS3: 7.5
debian
около 6 лет назад

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libr ...

CVSS3: 7.5
github
около 6 лет назад

Improper Restriction of XML External Entity Reference in jackson-mapper-asl

CVSS3: 5.9
fstec
около 6 лет назад

Уязвимость компонента org.codehaus.jackson библиотеки jackson-mapper-asl, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 68%
0.00563
Низкий

5.9 Medium

CVSS3

Уязвимость CVE-2019-10172