QID 982315
QID 982315: Java (maven) Security Update for com.fasterxml.jackson.core:jackson-databind (GHSA-mx9v-gmh4-mgqw)
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mx9v-gmh4-mgqw for updates pertaining to this vulnerability.
Vendor References
- GHSA-mx9v-gmh4-mgqw -
github.com/advisories/GHSA-mx9v-gmh4-mgqw
CVEs related to QID 982315
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mx9v-gmh4-mgqw | com.fasterxml.jackson.core:jackson-databind |
|