Candidate: CVE-2016-3720 PublicDate: 2016-06-10 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3720 https://github.com/FasterXML/jackson-dataformat-xml/commit/f0f19a4c924d9db9a1e2830434061c8640092cc0 (2.7.4) Description: XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_jackson-dataformat-xml: upstream_jackson-dataformat-xml: needs-triage precise_jackson-dataformat-xml: DNE precise/esm_jackson-dataformat-xml: DNE trusty_jackson-dataformat-xml: DNE trusty/esm_jackson-dataformat-xml: DNE vivid/stable-phone-overlay_jackson-dataformat-xml: DNE vivid/ubuntu-core_jackson-dataformat-xml: DNE wily_jackson-dataformat-xml: ignored (reached end-of-life) xenial_jackson-dataformat-xml: ignored (end of standard support, was needed) yakkety_jackson-dataformat-xml: ignored (reached end-of-life) zesty_jackson-dataformat-xml: ignored (reached end-of-life) artful_jackson-dataformat-xml: ignored (reached end-of-life) bionic_jackson-dataformat-xml: not-affected (2.7.4-1) cosmic_jackson-dataformat-xml: not-affected (2.7.4-1) disco_jackson-dataformat-xml: not-affected (2.7.4-1) eoan_jackson-dataformat-xml: not-affected (2.7.4-1) focal_jackson-dataformat-xml: not-affected (2.7.4-1) groovy_jackson-dataformat-xml: not-affected (2.7.4-1) hirsute_jackson-dataformat-xml: not-affected (2.7.4-1) impish_jackson-dataformat-xml: not-affected (2.7.4-1) jammy_jackson-dataformat-xml: not-affected (2.7.4-1) devel_jackson-dataformat-xml: not-affected (2.7.4-1)