QID 980320
QID 980320: Java (maven) Security Update for com.fasterxml.jackson.core:jackson-databind (GHSA-mc6h-4qgp-37qh)
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mc6h-4qgp-37qh for updates pertaining to this vulnerability.
Vendor References
- GHSA-mc6h-4qgp-37qh -
github.com/advisories/GHSA-mc6h-4qgp-37qh
CVEs related to QID 980320
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mc6h-4qgp-37qh | com.fasterxml.jackson.core:jackson-databind |
|