General data-binding functionality for Jackson: works on core streaming API
Language
JAVA
Vulnerability
Remote Code Execution (RCE)
Vulnerability description
jackson-databind is susceptible to deserialisation vulnerability. The vulnerability is due to the lack of openjpa class blockage, allowing a remote attacker to leverage this vulnerability to execute arbitrary code.
Veracode Software Composition Analysis
openjpa
class blockage, allowing a remote attacker to leverage this vulnerability to execute arbitrary code.Links: