Lucene search

K
redhatcveRedhat.comRH:CVE-2018-14718
HistoryJan 13, 2022 - 6:38 a.m.

CVE-2018-14718

2022-01-1306:38:13
redhat.com
access.redhat.com
93
jackson-databind
polymorphic deserialization
slf4j classes
arbitrary code

EPSS

0.037

Percentile

91.8%

A flaw was discovered in jackson-databind, where it would permit polymorphic deserialization of a malicious object using slf4j classes. An attacker could use this flaw to execute arbitrary code.