Back to search
CVE-2019-10172
Published: Nov 18, 2019
Modified: Aug 4, 2024
PUBLISHED
CVSS v3.0
5.9
MEDIUM
Description
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
| Vendor | Product | Versions |
|---|---|---|
Redhat | jackson-mapper-asl | affected 1.9.x |
Weaknesses (CWE)
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10172
x_refsource_CONFIRM
[debian-lts-announce] 20200131 [SECURITY] [DLA 2091-1] libjackson-json-java security update
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20200824 [SECURITY] [DLA 2342-1] libjackson-json-java security update
mailing-list
x_refsource_MLIST
[spark-issues] 20210223 [jira] [Created] (SPARK-34511) Current Security vulnerabilities in spark libraries
mailing-list
x_refsource_MLIST
[hadoop-user] 20210317 jackson-mapper-asl vulnerability at Hadoop
mailing-list
x_refsource_MLIST
[hive-dev] 20210318 CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now