First published: Mon Nov 09 2020(Updated: )
This release of Red Hat build of Eclipse Vert.x 3.9.4 includes security updates, bug fixes, and enhancements. For more information, see the release notes listed in the References section.<br>Security Fix(es):<br><li> jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)(CVE-2020-25649)</li> For more details about the security issues and their impact, the CVSS score, acknowledgements, and other related information, see the CVE pages listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Vert.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:4379 is classified as important.
To fix RHSA-2020:4379, update to the latest version of Red Hat build of Eclipse Vert.x.
RHSA-2020:4379 addresses a security fix in the Jackson Databind library related to insecure entity expansion.
RHSA-2020:4379 specifically applies to version 3.9.4 of Eclipse Vert.x.
RHSA-2020:4379 was released in December 2020.