org.codehaus.jackson:jackson-mapper-asl@1.6.5 vulnerabilities
-
latest version
1.9.13
-
first published
15 years ago
-
latest version published
11 years ago
-
licenses detected
- [0.9.6,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the org.codehaus.jackson:jackson-mapper-asl package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
org.codehaus.jackson:jackson-mapper-asl is a high-performance data binding package built on Jackson JSON processor. Affected versions of this package are vulnerable to Improper Input Validation which results in several instances of deserialization of untrusted data. This issue is parallel to vulnerabilities reported and fixed in jackson-databind (CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086). Although no fix is available for codehaus, this vulnerability can be remediated by using a fixed version of jackson-databind. How to fix Improper Input Validation? There is no fixed version for |
[0,)
|
org.codehaus.jackson:jackson-mapper-asl is a high-performance data binding package built on Jackson JSON processor. Affected versions of this package are vulnerable to XML External Entity (XXE) Injection.
via the How to fix XML External Entity (XXE) Injection? There is no fixed version for For |
[0,)
|