org.glassfish.jersey.media:jersey-media-jaxb@2.27 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.glassfish.jersey.media:jersey-media-jaxb package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
XML Entity Expansion

org.glassfish.jersey.media:jersey-media-jaxb is a REST framework that provides JAX-RS Reference Implementation and more.

Affected versions of this package are vulnerable to XML Entity Expansion. The SAXParserFactory provider is only disabling external entities, and does not protect against XML entity expansion.

How to fix XML Entity Expansion?

Upgrade org.glassfish.jersey.media:jersey-media-jaxb to version 2.31 or higher.

[,2.31)