Deserialization of untrusted data in jackson-databind
High severity
GitHub Reviewed
Published
Jan 20, 2021
to the GitHub Advisory Database
•
Updated Mar 15, 2024
Package
Affected versions
>= 2.7.0, < 2.9.10.7
< 2.6.7.5
Patched versions
2.9.10.7
2.6.7.5
Description
Published by the National Vulnerability Database
Jan 19, 2021
Reviewed
Jan 20, 2021
Published to the GitHub Advisory Database
Jan 20, 2021
Last updated
Mar 15, 2024
A flaw was found in jackson-databind before 2.9.10.7 and 2.6.7.5. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
References