Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22481
HistoryFeb 11, 2020 - 2:42 a.m.

Remote Code Execution

2020-02-1102:42:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

0.03 Low

EPSS

Percentile

91.0%

jackson-databind is vulnerable to remote code execution. The vulnerability exists because it does not restrict the data sources for the org.apache.xbean.propertyeditor.JndiConverter object type, leading to deserialisation of arbitrary data from external untrusted sources which would allow an attacker to execute arbitrary code.

References