Summary: A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes. Reference Links(if available): https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10172 https://lists.debian.org/debian-lts-announce/2020/01/msg00037.html https://lists.apache.org/thread.html/[email protected]%3Ccommits.cassandra.apache.org%3E https://lists.apache.org/thread.html/[email protected]%3Ccommits.cassandra.apache.org%3E https://lists.apache.org/thread.html/[email protected]%3Ccommits.cassandra.apache.org%3E CVSS Score (if available) v2: / MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N v3: / HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Links to Exploits(if available) Post navigation CVE-2019-10172 CVE-2021-22149