CVE-2020-25649
HIGHjackson-databind 2.6.0-2.6.7.3 - XML External Entity Injection
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2020-25649. PoCs published by dawetmaster, andikahilmy.
AI-analyzed exploit summary The repository contains a partial copy of the Jackson Databind library but lacks any exploit code or technical analysis related to CVE-2020-25649. It appears to be a placeholder or incomplete project.
Description
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
Exploits (2)
The repository contains a partial copy of the Jackson Databind library but lacks any exploit code or technical analysis related to CVE-2020-25649. It appears to be a placeholder or incomplete project.
The repository contains a partial copy of the Jackson Databind library but lacks any exploit code or technical analysis specific to CVE-2020-25649. It appears to be a placeholder or incomplete project.
References (71)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N