First published: Tue Apr 19 2016(Updated: )
It was reported that XmlMapper in jackson-dataformat-xml is vulnerable to XXE attack ("Improper Restriction of XML External Entity Reference").
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jackson-dataformat-xml | <2.7.4 | 2.7.4 |
Fedora | =24 | |
FasterXML Jackson Dataformat XML | <=2.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3720 is classified as a medium severity vulnerability due to its potential for XXE attacks.
To fix CVE-2016-3720, upgrade the jackson-dataformat-xml package to version 2.7.4 or later.
CVE-2016-3720 affects jackson-dataformat-xml versions prior to 2.7.4 and Fedora 24.
CVE-2016-3720 is associated with XML External Entity (XXE) attacks that can lead to unauthorized data access.
CVE-2016-3720 specifically affects applications relying on jackson-dataformat-xml across various operating systems including Fedora.