First published: Tue Apr 19 2016(Updated: )
It was reported that XmlMapper in jackson-dataformat-xml is vulnerable to XXE attack ("Improper Restriction of XML External Entity Reference").
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jackson-dataformat-xml | <2.7.4 | 2.7.4 |
Fedoraproject Fedora | =24 | |
Fasterxml Jackson-dataformat-xml | <=2.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.