QID 982715

QID 982715: Java (maven) Security Update for com.fasterxml.jackson.core:jackson-databind (GHSA-mph4-vhrx-mv67)

FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-mph4-vhrx-mv67 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982715

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mph4-vhrx-mv67 com.fasterxml.jackson.core:jackson-databind URL Logo github.com/advisories/GHSA-mph4-vhrx-mv67