XML External Entity (XXE) Injection in Jackson Databind
High severity
GitHub Reviewed
Published
Feb 18, 2021
to the GitHub Advisory Database
•
Updated Mar 15, 2024
Package
Affected versions
>= 2.7.0.0, <= 2.9.10.6
>= 2.10.0.0, <= 2.10.5.0
>= 2.6.0, <= 2.6.7.3
Patched versions
2.9.10.7
2.10.5.1
2.6.7.4
Description
Published by the National Vulnerability Database
Dec 3, 2020
Reviewed
Feb 18, 2021
Published to the GitHub Advisory Database
Feb 18, 2021
Last updated
Mar 15, 2024
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
References