A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-2406-1 | jackson-databind security update |
![]() |
DLA-2638-1 | jackson-databind security update |
![]() |
EUVD-2021-0525 | A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity. |
![]() |
GHSA-288c-cq4h-88gq | XML External Entity (XXE) Injection in Jackson Databind |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T15:40:36.648Z
Reserved: 2020-09-16T00:00:00
Link: CVE-2020-25649

No data.

Status : Modified
Published: 2020-12-03T17:15:12.503
Modified: 2024-11-21T05:18:20.343
Link: CVE-2020-25649


No data.