QID 982702
QID 982702: Java (maven) Security Update for com.fasterxml.jackson.core:jackson-databind (GHSA-cf6r-3wgc-h863)
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cf6r-3wgc-h863 for updates pertaining to this vulnerability.
Vendor References
- GHSA-cf6r-3wgc-h863 -
github.com/advisories/GHSA-cf6r-3wgc-h863
CVEs related to QID 982702
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cf6r-3wgc-h863 | com.fasterxml.jackson.core:jackson-databind |
|