CVE-2019-10172

HIGH

org.codehaus.jackson:jackson-mapper-asl:1.9.x - XXE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-10172. PoCs published by rusakovichma.

AI-analyzed exploit summary This repository demonstrates CVE-2019-10172, an XXE vulnerability in Jackson's DOMDeserializer. It includes vulnerable and secure implementations, along with test cases that show the exploit (XXE attack) and mitigation (secure processing).

Description

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

Exploits (1)

nomisec WORKING POC 1 stars
by rusakovichma · poc
https://github.com/rusakovichma/CVE-2019-10172

This repository demonstrates CVE-2019-10172, an XXE vulnerability in Jackson's DOMDeserializer. It includes vulnerable and secure implementations, along with test cases that show the exploit (XXE attack) and mitigation (secure processing).

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Jackson (com.codehaus.jackson) versions with vulnerable DOMDeserializer
No auth needed
Prerequisites: Application using vulnerable Jackson library for XML deserialization
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (37)

Core 37
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10172
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/01/msg00037.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/08/msg00039.html

Scores

CVSS v3 7.5
EPSS 0.0056
EPSS Percentile 68.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-611
Status published
Products (7)
apache/spark 3.0.1
debian/debian_linux 8.0
debian/debian_linux 9.0
fasterxml/jackson-mapper-asl 1.9.0 - 1.9.13
org.codehaus.jackson/jackson-mapper-asl 0Maven
redhat/jboss_enterprise_application_platform 7.0
redhat/jboss_fuse 7.0.0
Published Nov 18, 2019
Tracked Since Feb 18, 2026