Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20547
HistoryJun 14, 2019 - 3:58 a.m.

Unsafe Deserialization

2019-06-1403:58:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.533 Medium

EPSS

Percentile

97.6%

jackson-databind is vulnerable to arbitrary code execution via unsafe deserrialization. Lack of object validation before deserialization allows an attacker to execute arbitrary code using polymorphic deserialization of a malicious gadget type.

References