Количество 6
Количество 6
CVE-2018-14720
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
CVE-2018-14720
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
CVE-2018-14720
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
CVE-2018-14720
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to c ...
GHSA-x2w5-5m2g-7h5m
XML External Entity Reference (XXE) in jackson-databind
BDU:2019-01756
Уязвимость библиотеки jackson-databind, связанная с ошибкой ограничения XML-ссылок на внешние объекты, позволяющая нарушителю осуществить XXE-атаку
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-14720 FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization. | CVSS3: 9.8 | 3% Низкий | около 7 лет назад | |
CVE-2018-14720 FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization. | CVSS3: 7.5 | 3% Низкий | больше 7 лет назад | |
CVE-2018-14720 FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization. | CVSS3: 9.8 | 3% Низкий | около 7 лет назад | |
CVE-2018-14720 FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to c ... | CVSS3: 9.8 | 3% Низкий | около 7 лет назад | |
GHSA-x2w5-5m2g-7h5m XML External Entity Reference (XXE) in jackson-databind | CVSS3: 9.8 | 3% Низкий | около 7 лет назад | |
BDU:2019-01756 Уязвимость библиотеки jackson-databind, связанная с ошибкой ограничения XML-ссылок на внешние объекты, позволяющая нарушителю осуществить XXE-атаку | CVSS3: 9.8 | 3% Низкий | больше 7 лет назад |
Уязвимостей на страницу