QID 982715
QID 982715: Java (maven) Security Update for com.fasterxml.jackson.core:jackson-databind (GHSA-mph4-vhrx-mv67)
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mph4-vhrx-mv67 for updates pertaining to this vulnerability.
Vendor References
- GHSA-mph4-vhrx-mv67 -
github.com/advisories/GHSA-mph4-vhrx-mv67
CVEs related to QID 982715
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mph4-vhrx-mv67 | com.fasterxml.jackson.core:jackson-databind |
|