REDHAT-BUG-1378673: SSRF
Published Sep 23, 2016
·Updated
A flaw was found in jackson-dataformat-xml's XmlMapper which allows XXE Out of Band attack. An attacker could use this flaw to launch a SSRF attack.
Affected Software
1 affected component
fasterxml jackson-dataformat-xml
Event History
Sep 23, 2016
Data Sourced
via Red Hat·03:47 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1378673?
The severity of REDHAT-BUG-1378673 is considered critical due to its potential for XXE Out of Band attacks.
2
How do I fix REDHAT-BUG-1378673?
To fix REDHAT-BUG-1378673, you should update the jackson-dataformat-xml library to the latest version that addresses this vulnerability.
3
What type of attack is possible with REDHAT-BUG-1378673?
REDHAT-BUG-1378673 allows for XML External Entity (XXE) attacks, which can lead to Server-Side Request Forgery (SSRF) exploits.
4
Which software is affected by REDHAT-BUG-1378673?
The affected software for REDHAT-BUG-1378673 is FasterXML's jackson-dataformat-xml.
5
Can REDHAT-BUG-1378673 be exploited remotely?
Yes, REDHAT-BUG-1378673 can be exploited remotely, making it crucial to apply fixes promptly.