Candidate: CVE-2016-7051 PublicDate: 2017-04-14 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7051 https://bugzilla.redhat.com/show_bug.cgi?id=1378673 Description: XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Adith Sudhakar Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N [8.6 HIGH] Patches_jackson-dataformat-xml: upstream_jackson-dataformat-xml: needs-triage precise_jackson-dataformat-xml: DNE precise/esm_jackson-dataformat-xml: DNE trusty_jackson-dataformat-xml: DNE trusty/esm_jackson-dataformat-xml: DNE vivid/stable-phone-overlay_jackson-dataformat-xml: DNE vivid/ubuntu-core_jackson-dataformat-xml: DNE xenial_jackson-dataformat-xml: ignored (end of standard support, was needed) yakkety_jackson-dataformat-xml: ignored (reached end-of-life) zesty_jackson-dataformat-xml: ignored (reached end-of-life) artful_jackson-dataformat-xml: ignored (reached end-of-life) bionic_jackson-dataformat-xml: not-affected (2.8.5-1) cosmic_jackson-dataformat-xml: not-affected (2.8.5-1) disco_jackson-dataformat-xml: not-affected (2.8.5-1) eoan_jackson-dataformat-xml: not-affected (2.8.5-1) focal_jackson-dataformat-xml: not-affected (2.8.5-1) groovy_jackson-dataformat-xml: not-affected (2.8.5-1) hirsute_jackson-dataformat-xml: not-affected (2.8.5-1) impish_jackson-dataformat-xml: not-affected (2.8.5-1) jammy_jackson-dataformat-xml: not-affected (2.8.5-1) devel_jackson-dataformat-xml: not-affected (2.8.5-1)