RHSA-2020:4312: Important: rh-maven35-jackson-databind security update
The jackson-databind package provides general data-binding functionality for Jackson, which works on top of Jackson core streaming API.Security Fix(es): jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) (CVE-2020-25649) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4312?
The severity of RHSA-2020:4312 is classified as important.
How do I fix RHSA-2020:4312?
To fix RHSA-2020:4312, update the rh-maven35-jackson-databind package to version 2.7.6-2.12.el7.
What vulnerabilities does RHSA-2020:4312 address?
RHSA-2020:4312 addresses an XML external entity (XXE) vulnerability in the jackson-databind package.
Which versions are affected by RHSA-2020:4312?
Versions of rh-maven35-jackson-databind prior to 2.7.6-2.12.el7 are affected by RHSA-2020:4312.
Who is impacted by RHSA-2020:4312?
Organizations using the rh-maven35-jackson-databind package that haven't applied the update are at risk from RHSA-2020:4312.