Lucene search

K
redhatcveRedhat.comRH:CVE-2018-12022
HistoryApr 09, 2020 - 12:17 p.m.

CVE-2018-12022

2020-04-0912:17:35
redhat.com
access.redhat.com
14

0.008 Low

EPSS

Percentile

81.4%

A vulnerability was discovered in jackson-databind where it would permit deserialization of a malicious object using Jodd DB connection classes when using DefaultTyping. An attacker could use this flaw to achieve remote code execution under certain circumstances.