PT-2019-5307 · Codehaus+3 · Jackson-Mapper-Asl+3

Mark Denihan

·

Published

2019-11-18

·

Updated

2025-04-23

·

CVE-2019-10172

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions org.codehaus.jackson:jackson-mapper-asl versions 1.9.x
Description A flaw was found in the org.codehaus.jackson:jackson-mapper-asl library, related to incorrect restriction of XML external entity references. This issue is similar to previously identified vulnerabilities and can be exploited by a remote attacker to impact data integrity.
Recommendations For org.codehaus.jackson:jackson-mapper-asl version 1.9.x, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XXE

Weakness Enumeration

Related Identifiers

BDU:2020-02254
CVE-2019-10172
DLA-2091-1
DLA-2342-1
GHSA-R6J9-8759-G62W
OESA-2021-1342
RHSA-2020:2058
RHSA-2020:2059
RHSA-2020:2060
RHSA-2020:2511
RHSA-2020:2512
RHSA-2020:2513
USN-4741-1

Affected Products

Astra Linux
Confluence
Ubuntu
Jackson-Mapper-Asl