General data-binding functionality for Jackson: works on core streaming API
Language
JAVA
Vulnerability
Unsafe Deserialization
Vulnerability description
jackson-databind is vulnerable to arbitrary code execution via unsafe deserrialization. Lack of object validation before deserialization allows an attacker to execute arbitrary code using polymorphic deserialization of a malicious gadget type.
Veracode Software Composition Analysis
Links: