Lucene search

K
osvGoogleOSV:GHSA-X2W5-5M2G-7H5M
HistoryJan 04, 2019 - 7:09 p.m.

XML External Entity Reference (XXE) in jackson-databind

2019-01-0419:09:46
Google
osv.dev
42

EPSS

0.008

Percentile

82.2%

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.

References