Known vulnerabilities in jackson-dataformat-xml
Vendor:
FasterXML
Software:
jackson-dataformat-xml
Software CPE:
cpe:2.3:a:fasterxml:jackson-dataformat-xml:*:*:*:*:*:jackson-databind:*:*
Website:
https://github.com/FasterXML
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.2.1
3.1.5
2.18.9
2.22.1
2.21.5
3.2.0
2.22.0
3.1.4
2.21.4
2.18.8
3.1.3
2.21.3
2.18.7
3.1.2
3.1.1
2.21.2
2.21.1
2.18.6
3.1.0
3.0.4
2.20.2
2.21.0
3.0.3
3.0.2
2.20.1
2.19.4
2.19.3
2.18.5
3.0.1
2.20.0
2.19.2
2.19.1
2.18.4
2.19.0
3.0.0
2.18.3
2.18.2
2.17.3
2.18.1
2.18.0
2.17.2
2.17.1
2.16.2
2.17.0
2.15.4
2.16.1
2.16.0
2.15.3
2.15.2
2.15.1
2.14.3
2.15.0
2.14.1
2.13.5
2.14.2
2.14.0
2.13.4
2.12.7
2.13.3
2.13.2
2.13.1
2.12.6
2.12.5
2.13.0
2.12.4
2.12.3
2.12.2
2.12.1
2.11.4
2.12.0
2.11.3
2.11.2
2.10.5
2.11.1
2.11.0.rc1
2.11.0
2.10.4
2.10.3
2.10.2
2.10.1
2.10.0.pr3
2.10.0.pr2
2.10.0.pr1
2.10.0
2.9.10
2.9.9
2.9.8
2.9.7
2.9.6
2.9.5
2.9.4
2.9.3
2.9.2
2.9.1
2.9.0.pr4
2.9.0.pr3
2.9.0.pr2
2.9.0.pr1
2.9.0
2.8.11
2.8.10
2.8.9
2.8.8
2.8.7
2.8.6
2.8.5
2.8.4
2.8.3
2.8.2
2.8.1
2.8.0.rc2
2.8.0.rc1
2.8.0
2.7.9
2.7.8
2.7.7
2.7.6
2.7.5
2.7.4
2.7.3
2.7.2
2.7.1
2.7.0
2.6.7
2.6.6
2.6.5
2.6.4
2.6.3
2.6.2
2.6.1
2.6.0
2.5.5
2.5.4
2.5.3
2.5.2
2.5.1
2.5.0
2.4.6
2.4.5
2.4.4
2.4.3
2.4.2
2.4.1
2.4.0
2.3.5
2.3.4
2.3.3
2.3.2
2.3.1
2.3.0
2.2.4
2.2.3
2.2.2
2.2.1
2.2.0
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0
2.0.6
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
2.0.0
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU27704 - Server-Side Request Forgery (SSRF) CVE-2016-7051 |
CWE-918 | High | 2.7.8, 2.8.4 | 12.05.2020 |
SB2017041406 SB2019020720 |
||
| #VU27703 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2016-3720 |
CWE-611 | High | 2.7.4 | 12.05.2020 |
SB2016061003 SB2022101121 SB2021091803 and 7 more |