Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-10172. PoCs published by rusakovichma.
AI-analyzed exploit summary This repository demonstrates CVE-2019-10172, an XXE vulnerability in Jackson's DOMDeserializer. It includes vulnerable and secure implementations, along with test cases that show the exploit (XXE attack) and mitigation (secure processing).
Description
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
Exploits (1)
This repository demonstrates CVE-2019-10172, an XXE vulnerability in Jackson's DOMDeserializer. It includes vulnerable and secure implementations, along with test cases that show the exploit (XXE attack) and mitigation (secure processing).
References (37)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N