1.9.13
15 years ago
11 years ago
Known vulnerabilities in the org.codehaus.jackson:jackson-mapper-asl package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.codehaus.jackson:jackson-mapper-asl is a high-performance data binding package built on Jackson JSON processor. Affected versions of this package are vulnerable to Improper Input Validation which results in several instances of deserialization of untrusted data. This issue is parallel to vulnerabilities reported and fixed in jackson-databind (CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086). Although no fix is available for codehaus, this vulnerability can be remediated by using a fixed version of jackson-databind. How to fix Improper Input Validation? There is no fixed version for | [0,) |
org.codehaus.jackson:jackson-mapper-asl is a high-performance data binding package built on Jackson JSON processor. Affected versions of this package are vulnerable to XML External Entity (XXE) Injection.
via the How to fix XML External Entity (XXE) Injection? There is no fixed version for For | [0,) |