Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21523
HistorySep 16, 2019 - 7:58 a.m.

Deserialization Of Untrusted Data

2019-09-1607:58:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

0.004 Low

EPSS

Percentile

74.0%

FasterXML jackson-databind is vulnerable to deserialization of untrusted data. It causes polymorphic typing because there are more than one association gadget types related to com.zaxxer.hikari.HikariDataSource by default. This vulnerability is different from CVE-2019-14540. A remote attacker can gain unauthorized access to sensitive information on the system.

References