RHSA-2020:4379HighCVSS 7.5

Red Hat Security Advisory: Red Hat build of Eclipse Vert.x 3.9.4 security update

Published
November 9, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2020-25649 — jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)

🎯 Affected products1

  • Vert.x 3.9.4

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Workaround: There is currently no known mitigation for this flaw.

🔗 References (6)