General data-binding functionality for Jackson: works on core streaming API
Language
JAVA
Vulnerability
Remote Code Execution (RCE)
Vulnerability description
jackson-databind is vulnerable to remote code execution (RCE). The attack is possible due to lack of proper handling of gadget type conversion when ehcache is used.
Veracode Software Composition Analysis
ehcache
is used.Links: