QID 982256
QID 982256: Java (maven) Security Update for com.fasterxml.jackson.core:jackson-databind (GHSA-6fpp-rgj9-8rwc)
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6fpp-rgj9-8rwc for updates pertaining to this vulnerability.
Vendor References
- GHSA-6fpp-rgj9-8rwc -
github.com/advisories/GHSA-6fpp-rgj9-8rwc
CVEs related to QID 982256
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6fpp-rgj9-8rwc | com.fasterxml.jackson.core:jackson-databind |
|