FasterXML/jackson-dataformat-xml

FasterXML/jackson-dataformat-xml

Releases188
Frequency3 weeks 6 days
Last Release
Stars624
Extension for Jackson JSON processor that adds support for serializing POJOs as XML (and deserializing from XML) as an alternative to JSON

CVE History

CVEPublishedCVSS v3CVSS v2
8.6 HIGH5 MEDIUM

XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.