Server-side request forgery (SSRF) In com.fasterxml.jackson.core:jackson-databind
Description
Server-Side Request Forgery (SSRF) in jackson-databind FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 2.9.7, 2.8.11.3, 2.7.9.5 | ||
debian 11 | 2.9.8-1 | ||
debian 12 | 2.9.8-1 | ||
debian 13 | 2.9.8-1 | ||
debian 14 | 2.9.8-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17.