QID 982327
QID 982327: Java (maven) Security Update for com.fasterxml.jackson.core:jackson-databind (GHSA-x2w5-5m2g-7h5m)
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x2w5-5m2g-7h5m for updates pertaining to this vulnerability.
Vendor References
- GHSA-x2w5-5m2g-7h5m -
github.com/advisories/GHSA-x2w5-5m2g-7h5m
CVEs related to QID 982327
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x2w5-5m2g-7h5m | com.fasterxml.jackson.core:jackson-databind |
|