CVE-2018-14720

CRITICAL9.8EPSS 3.4%

XML External Entity Reference (XXE) in jackson-databind

發布日:2019/1/4修改日:2026/4/28

描述

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(35)