CVE-2016-7051
14.04.2017, 18:59
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.Enginsight
| Vendor | Product | Version |
|---|---|---|
| fasterxml | jackson-dataformat-xml | 𝑥 < 2.7.8 |
| fasterxml | jackson-dataformat-xml | 2.8.0 |
| fasterxml | jackson-dataformat-xml | 2.8.0:rc1 |
| fasterxml | jackson-dataformat-xml | 2.8.0:rc2 |
| fasterxml | jackson-dataformat-xml | 2.8.1 |
| fasterxml | jackson-dataformat-xml | 2.8.2 |
| fasterxml | jackson-dataformat-xml | 2.8.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| jackson-dataformat-xml |
|
References