Critical severity9.8NVD Advisory· Published Jun 10, 2016· Updated Jun 17, 2026
CVE-2016-3720
CVE-2016-3720
Description
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.fasterxml.jackson.dataformat:jackson-dataformat-xmlMaven | < 2.7.4 | 2.7.4 |
Affected products
3- cpe:2.3:a:fasterxml:jackson-dataformat-xml:*:*:*:*:*:*:*:*Range: <=2.7.3
- cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- lists.fedoraproject.org/pipermail/package-announce/2016-May/184561.htmlnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-hmq6-frv3-4727ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2016-3720ghsaADVISORY
News mentions
0No linked articles in our index yet.