CVE-2016-3720
jackson-dataformat-xml vulnerable to XML external entity (XXE)
Description
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.
Base CVSS
9.8
EPSS Score
0.21%
Introduced Version
0.5.0
Fix Available
2.7.4
Available Patches
Package
CVEs Fixed
Lines of Code Changed