QID 982704
QID 982704: Java (maven) Security Update for com.fasterxml.jackson.core:jackson-databind (GHSA-qr7j-h6gg-jmgc)
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qr7j-h6gg-jmgc for updates pertaining to this vulnerability.
Vendor References
- GHSA-qr7j-h6gg-jmgc -
github.com/advisories/GHSA-qr7j-h6gg-jmgc
CVEs related to QID 982704
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qr7j-h6gg-jmgc | com.fasterxml.jackson.core:jackson-databind |
|