Lucene search

K
osvGoogleOSV:GHSA-R3GR-CXRF-HG25
HistoryDec 09, 2021 - 7:15 p.m.

Serialization gadgets exploit in jackson-databind

2021-12-0919:15:11
Google
osv.dev
93

0.003 Low

EPSS

Percentile

66.1%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.