Server-Side Request Forgery (SSRF) in jackson-dataformat-xml - CVE-2016-7051

 

Server-Side Request Forgery (SSRF) in jackson-dataformat-xml - CVE-2016-7051

Published: May 12, 2020


Vulnerability identifier: #VU27704
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2016-7051
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input within XmlMapper when processing DTD data. A remote non-authenticated attacker can pass specially crafted XML data and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

jackson-dataformat-xml
Fedora
bouncycastle
jackson-parent
jackson-dataformats-binary
jackson-modules-base
jackson-module-jsonSchema
jackson-jaxrs-providers
jackson-datatypes-collections
jackson-datatype-joda
jackson-datatype-jdk8
jackson-dataformats-text
jackson-dataformat-xml
jackson-databind
jackson-core
jackson-bom
jackson-annotations
eclipse-jgit
eclipse-linuxtools

How to mitigate CVE-2016-7051

Install updates from vendor's website.

jackson-dataformat-xml - addressed in versions 2.7.8, 2.8.4
bouncycastle - update to 1.61-1.fc29
jackson-parent - update to 2.9.1.2-1.fc29
jackson-dataformats-binary - update to 2.9.8-1.fc29
jackson-modules-base - update to 2.9.8-1.fc29
jackson-module-jsonSchema - update to 2.9.8-1.fc29
jackson-jaxrs-providers - update to 2.9.8-1.fc29
jackson-datatypes-collections - update to 2.9.8-1.fc29
jackson-datatype-joda - update to 2.9.8-1.fc29
jackson-datatype-jdk8 - update to 2.9.8-1.fc29
jackson-dataformats-text - update to 2.9.8-1.fc29
jackson-dataformat-xml - update to 2.9.8-1.fc29
jackson-databind - update to 2.9.8-1.fc29
jackson-core - update to 2.9.8-1.fc29
jackson-bom - update to 2.9.8-1.fc29
jackson-annotations - update to 2.9.8-1.fc29
eclipse-jgit - update to 5.2.0-4.fc29
eclipse-linuxtools - update to 7.1.0-3.fc29

External References

Related Security Bulletins