VDB
DEBIAN-CVE-2018-14720
DEBIAN-CVE-2018-14720
PUBLISHED
CVSS 9.800000190734863 CRITICAL
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
Risk Scores
CVSS v3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | jackson-databind | 0, 0, 0 |
| Debian:13 | jackson-databind | 0, 0, 0 |
| Debian:12 | jackson-databind | 0, 0, 0 |
| Debian:14 | jackson-databind | 0, 0, 0 |
Timeline
- Jan 2, 2019 CVE Published
- Apr 28, 2026 CVE Updated