Deserialization of Untrusted Data in jackson-databind
Critical severity
GitHub Reviewed
Published
Jul 16, 2019
to the GitHub Advisory Database
•
Updated Mar 1, 2024
Package
Affected versions
>= 2.9.0, < 2.9.6
>= 2.0.0, <= 2.7.9.3
>= 2.8.0, <= 2.8.11.1
Patched versions
2.9.6
2.7.9.4
2.8.11.2
Description
Published by the National Vulnerability Database
Jul 9, 2019
Reviewed
Jul 16, 2019
Published to the GitHub Advisory Database
Jul 16, 2019
Last updated
Mar 1, 2024
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
References