Description
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.
Remediation
References
http://www.securityfocus.com/bid/97688
https://bugzilla.redhat.com/show_bug.cgi?id=1378673
https://github.com/FasterXML/jackson-dataformat-xml/issues/211
Related Vulnerabilities
CVE-2018-8032 Vulnerability in maven package org.apache.axis:axis
CVE-2021-41246 Vulnerability in npm package express-openid-connect
CVE-2013-1965 Vulnerability in maven package org.apache.struts:struts2-showcase
CVE-2022-23307 Vulnerability in maven package org.apache.logging.log4j:log4j
CVE-2016-1000340 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on