Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 Maven

XML External Entity Reference (XXE) in jackson-databind

GHSA-x2w5-5m2g-7h5m · CVE-2018-14720

Published · Modified

Description

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes