DirectorySecurity Advisories
Sign In
Security Advisories

CGA-qvvv-vvhp-4fmh

Published

Last updated

https://images.chainguard.dev/security/CGA-qvvv-vvhp-4fmh
Package

hive

Latest Update
Fixed
Fixed Version

4.0.1-r1

Aliases
  • CVE-2018-14720
  • GHSA-x2w5-5m2g-7h5m

Severity

9.8

Critical

CVSS V3

Summary

XML External Entity Reference (XXE) in jackson-databind

Description

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images