XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.
| Software | From | Fixed in |
|---|---|---|
| fasterxml / jackson-dataformat-xml | - | 2.7.8 |
| fasterxml / jackson-dataformat-xml | 2.8.0 | 2.8.0.x |
| fasterxml / jackson-dataformat-xml | 2.8.0-rc1 | 2.8.0-rc1.x |
| fasterxml / jackson-dataformat-xml | 2.8.0-rc2 | 2.8.0-rc2.x |
| fasterxml / jackson-dataformat-xml | 2.8.1 | 2.8.1.x |
| fasterxml / jackson-dataformat-xml | 2.8.2 | 2.8.2.x |
| fasterxml / jackson-dataformat-xml | 2.8.3 | 2.8.3.x |
com.fasterxml.jackson.dataformat / jackson-dataformat-xml
|
- | 2.7.8 |
com.fasterxml.jackson.dataformat / jackson-dataformat-xml
|
2.8.0 | 2.8.4 |