Lucene search

K
osvGoogleOSV:GHSA-MC6H-4QGP-37QH
HistoryJun 18, 2020 - 2:44 p.m.

Deserialization of untrusted data in Jackson Databind

2020-06-1814:44:43
Google
osv.dev
13

0.034 Low

EPSS

Percentile

91.5%

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).