Data Mapper package is a high-performance data binding package
built on Jackson JSON processor
Path to dependency file: /atomhopper/pom.xml
Path to vulnerable library: /atomhopper/target/atomhopper-1.2.35-SNAPSHOT/WEB-INF/lib/jackson-mapper-asl-1.9.5.jar,/home/wss-scanner/.m2/repository/org/codehaus/jackson/jackson-mapper-asl/1.9.5/jackson-mapper-asl-1.9.5.jar
Data Mapper package is a high-performance data binding package
built on Jackson JSON processor
Path to dependency file: /atomhopper/pom.xml
Path to vulnerable library: /atomhopper/target/atomhopper-1.2.35-SNAPSHOT/WEB-INF/lib/jackson-mapper-asl-1.9.5.jar,/home/wss-scanner/.m2/repository/org/codehaus/jackson/jackson-mapper-asl/1.9.5/jackson-mapper-asl-1.9.5.jar
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.
:rescue_worker_helmet: Automatic Remediation is available for this issue
CVE-2019-10172
### Vulnerable Library - jackson-mapper-asl-1.9.5.jar
Data Mapper package is a high-performance data binding package
built on Jackson JSON processor
Path to dependency file: /atomhopper/pom.xml
Path to vulnerable library: /atomhopper/target/atomhopper-1.2.35-SNAPSHOT/WEB-INF/lib/jackson-mapper-asl-1.9.5.jar,/home/wss-scanner/.m2/repository/org/codehaus/jackson/jackson-mapper-asl/1.9.5/jackson-mapper-asl-1.9.5.jar
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
Vulnerable Library - jackson-mapper-asl-1.9.5.jar
Data Mapper package is a high-performance data binding package built on Jackson JSON processor
Path to dependency file: /atomhopper/pom.xml
Path to vulnerable library: /atomhopper/target/atomhopper-1.2.35-SNAPSHOT/WEB-INF/lib/jackson-mapper-asl-1.9.5.jar,/home/wss-scanner/.m2/repository/org/codehaus/jackson/jackson-mapper-asl/1.9.5/jackson-mapper-asl-1.9.5.jar
Found in HEAD commit: d0c49807860a8c07c922d8e19168bd6893aad298
Vulnerabilities
Details
CVE-2019-10202
### Vulnerable Library - jackson-mapper-asl-1.9.5.jarData Mapper package is a high-performance data binding package built on Jackson JSON processor
Path to dependency file: /atomhopper/pom.xml
Path to vulnerable library: /atomhopper/target/atomhopper-1.2.35-SNAPSHOT/WEB-INF/lib/jackson-mapper-asl-1.9.5.jar,/home/wss-scanner/.m2/repository/org/codehaus/jackson/jackson-mapper-asl/1.9.5/jackson-mapper-asl-1.9.5.jar
Dependency Hierarchy: - :x: **jackson-mapper-asl-1.9.5.jar** (Vulnerable Library)
Found in HEAD commit: d0c49807860a8c07c922d8e19168bd6893aad298
Found in base branch: master
### Reachability AnalysisThe vulnerable code is not reachable.
### Vulnerability DetailsA series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.
Publish Date: 2019-10-01
URL: CVE-2019-10202
### CVSS 3 Score Details (9.8)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Origin: https://lists.apache.org/thread/08302h5kp2l9ry2zq8vydomlhn0fg4j4
Release Date: 2019-10-01
Fix Resolution: com.fasterxml.jackson.core:jackson-databind:2.0.0
:rescue_worker_helmet: Automatic Remediation is available for this issueCVE-2019-10172
### Vulnerable Library - jackson-mapper-asl-1.9.5.jarData Mapper package is a high-performance data binding package built on Jackson JSON processor
Path to dependency file: /atomhopper/pom.xml
Path to vulnerable library: /atomhopper/target/atomhopper-1.2.35-SNAPSHOT/WEB-INF/lib/jackson-mapper-asl-1.9.5.jar,/home/wss-scanner/.m2/repository/org/codehaus/jackson/jackson-mapper-asl/1.9.5/jackson-mapper-asl-1.9.5.jar
Dependency Hierarchy: - :x: **jackson-mapper-asl-1.9.5.jar** (Vulnerable Library)
Found in HEAD commit: d0c49807860a8c07c922d8e19168bd6893aad298
Found in base branch: master
### Reachability AnalysisThe vulnerable code is not reachable.
### Vulnerability DetailsA flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
Publish Date: 2019-11-18
URL: CVE-2019-10172
### CVSS 3 Score Details (7.5)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: High - Availability Impact: None
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10172
Release Date: 2019-11-18
Fix Resolution: com.fasterxml.jackson.core:jackson-databind:2.0.0-RC1
:rescue_worker_helmet: Automatic Remediation is available for this issue:rescue_worker_helmet: Automatic Remediation is available for this issue.