CVE-2016-3720: XEE
It was reported that XmlMapper in jackson-dataformat-xml is vulnerable to XXE attack ("Improper Restriction of XML External Entity Reference").
Other sources
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3720?
CVE-2016-3720 is classified as a medium severity vulnerability due to its potential for XXE attacks.
How do I fix CVE-2016-3720?
To fix CVE-2016-3720, upgrade the jackson-dataformat-xml package to version 2.7.4 or later.
Which software versions are affected by CVE-2016-3720?
CVE-2016-3720 affects jackson-dataformat-xml versions prior to 2.7.4 and Fedora 24.
What type of attack is associated with CVE-2016-3720?
CVE-2016-3720 is associated with XML External Entity (XXE) attacks that can lead to unauthorized data access.
Is CVE-2016-3720 specific to any operating system?
CVE-2016-3720 specifically affects applications relying on jackson-dataformat-xml across various operating systems including Fedora.