Lucene search

K
osvGoogleOSV:GHSA-C2Q3-4QRH-FM48
HistoryJun 18, 2020 - 2:44 p.m.

Deserialization of untrusted data in Jackson Databind

2020-06-1814:44:50
Google
osv.dev
31

EPSS

0.034

Percentile

91.5%

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms).