Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21692
HistoryOct 14, 2019 - 5:13 a.m.

Remote Code Execution (RCE)

2019-10-1405:13:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.007

Percentile

80.2%

FasterXML jackson-databind is vulnerable to remote code execution (RCE). A polymorphic typing issue allows a remote attacker to execute arbitrary code through the JNDI service due to unsafe deserialization of objects related to the apache-log4j-extra classpath.

References