CVE-2019-10172

HIGH

org.codehaus.jackson:jackson-mapper-asl:1.9.x - XXE

Title source: llm

Description

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

Exploits (1)

nomisec WORKING POC 1 stars
by rusakovichma · poc
https://github.com/rusakovichma/CVE-2019-10172

References (37)

... and 17 more

Scores

CVSS v3 7.5
EPSS 0.0056
EPSS Percentile 68.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-611
Status published
Products (7)
apache/spark 3.0.1
debian/debian_linux 8.0
debian/debian_linux 9.0
fasterxml/jackson-mapper-asl 1.9.0 - 1.9.13
org.codehaus.jackson/jackson-mapper-asl 0Maven
redhat/jboss_enterprise_application_platform 7.0
redhat/jboss_fuse 7.0.0
Published Nov 18, 2019
Tracked Since Feb 18, 2026