Insecure deserialization In jackson-databind
Description
Deserialization of Untrusted Data in jackson-databind An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 2.9.8-1 | ||
debian 14 | 2.9.8-1 | ||
maven | 2.7.9.4, 2.8.11.2, 2.9.6 | ||
debian 13 | 2.9.8-1 | ||
debian 11 | 2.9.8-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14.