QID 981559
QID 981559: Java (maven) Security Update for com.fasterxml.jackson.core:jackson-databind (GHSA-h4rc-386g-6m85)
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h4rc-386g-6m85 for updates pertaining to this vulnerability.
Vendor References
- GHSA-h4rc-386g-6m85 -
github.com/advisories/GHSA-h4rc-386g-6m85
CVEs related to QID 981559
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h4rc-386g-6m85 | com.fasterxml.jackson.core:jackson-databind |
|