-
-
Notifications
You must be signed in to change notification settings - Fork 1.4k
Closed
Labels
CVEIssues related to public CVEs (security vuln reports)Issues related to public CVEs (security vuln reports)
Milestone
Description
Similar to other polymorphic types with no limits, but for XXE with jdom2.jar
, tracked as CVE-2019-12814
.
See https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 for description of the general problem.
Fixed in:
- 2.9.10
- 2.8.11.4
- 2.7.9.6
- 2.6.7.3
kcy1019
Metadata
Metadata
Assignees
Labels
CVEIssues related to public CVEs (security vuln reports)Issues related to public CVEs (security vuln reports)