Insecure deserialization In jackson-databind
Description
Polymorphic Typing issue in FasterXML jackson-databind
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10, 2.8.11.5, and 2.6.7.3. It is related to com.zaxxer.hikari.HikariConfig.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 2.10.0-1 | ||
debian 14 | 2.10.0-1 | ||
maven | 2.9.10, 2.8.11.5, 2.6.7.3 | ||
debian 11 | 2.10.0-1 | ||
debian 12 | 2.10.0-1 | ||
rpm rhel8 | 0:10.8.3-1.module+el8.2.0+5925+bad5981a |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23. 24. 25. 26. 27. 28. 29. 30. 31.