Arbitrary Code Execution in jackson-databind
Critical severity
GitHub Reviewed
Published
Jan 4, 2019
to the GitHub Advisory Database
•
Updated Sep 13, 2023
Package
Affected versions
>= 2.9.0, < 2.9.7
>= 2.8.0, <= 2.8.11.2
>= 2.0.0, <= 2.7.9.4
Patched versions
2.9.7
2.8.11.3
2.7.9.5
Description
Published by the National Vulnerability Database
Jan 2, 2019
Published to the GitHub Advisory Database
Jan 4, 2019
Reviewed
Jun 16, 2020
Last updated
Sep 13, 2023
FasterXML jackson-databind 2.x before 2.9.7, 2.8.11.3, and 2.7.9.5 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
References