Vulnerability Description
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fasterxml | Jackson-Mapper-Asl | >= 1.9.0, <= 1.9.13 |
| Redhat | Jboss Enterprise Application Platform | 7.0 |
| Redhat | Jboss Fuse | 7.0.0 |
| Debian | Debian Linux | 8.0 |
| Apache | Spark | 3.0.1 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10172Issue TrackingThird Party Advisory
- https://lists.apache.org/thread.html/r0066c1e862613de402fee04e81cbe00bcd64b64a27
- https://lists.apache.org/thread.html/r04ecadefb27cda84b699130b11b96427f1d8a7a406
- https://lists.apache.org/thread.html/r08e1b73fabd986dcd2ddd7d09480504d1472264bed
- https://lists.apache.org/thread.html/r0d8c3e32a0a2d8a0b6118f5b3487d363afdda80c99
- https://lists.apache.org/thread.html/r0fbf2c60967bc9f73d7f5a62ad3b955789f9a14b95
- https://lists.apache.org/thread.html/r1cc8bce2cf3dfce08a64c4fa20bf38d33b56ad995c
- https://lists.apache.org/thread.html/r1edabcfacdad42d3c830464e9cf07a9a489059a7b7
- https://lists.apache.org/thread.html/r1f07e61b3ebabd3e5b4aa97bf1b26d98b793fdfa29
- https://lists.apache.org/thread.html/r21ac3570ce865b8f1e5d26e492aeb714a6aaa53a0c
- https://lists.apache.org/thread.html/r25e25973e9577c62fd0221b4b52990851adf11cbe3
- https://lists.apache.org/thread.html/r33d25a342af84102903cd9dec8338a5bcba3ecfce1
- https://lists.apache.org/thread.html/r356592d9874ab4bc9da4754592f8aa6edc894c95e1
- https://lists.apache.org/thread.html/r37eb6579fa0bf94a72b6c978e2fee96f68a2b1b3ac
- https://lists.apache.org/thread.html/r385c35a7c6f4acaacf37fe22922bb8e2aed9d322d0
FAQ
What is CVE-2019-10172?
CVE-2019-10172 is a vulnerability with a CVSS score of 7.5 (HIGH). A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in differe...
How severe is CVE-2019-10172?
CVE-2019-10172 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10172?
Check the references section above for vendor advisories and patch information. Affected products include: Fasterxml Jackson-Mapper-Asl, Redhat Jboss Enterprise Application Platform, Redhat Jboss Fuse, Debian Debian Linux, Apache Spark.