org.glassfish.jersey.media:jersey-media-jaxb@2.26-b08 vulnerabilities

  • latest version

    3.1.10

  • latest non vulnerable version

  • first published

    10 years ago

  • latest version published

    2 months ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the org.glassfish.jersey.media:jersey-media-jaxb package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    XML Entity Expansion

    org.glassfish.jersey.media:jersey-media-jaxb is a REST framework that provides JAX-RS Reference Implementation and more.

    Affected versions of this package are vulnerable to XML Entity Expansion. The SAXParserFactory provider is only disabling external entities, and does not protect against XML entity expansion.

    How to fix XML Entity Expansion?

    Upgrade org.glassfish.jersey.media:jersey-media-jaxb to version 2.31 or higher.

    [,2.31)