Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22620
HistoryMar 03, 2020 - 3:42 a.m.

Deserialization Of Untrusted Object

2020-03-0303:42:59
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20

0.007 Low

EPSS

Percentile

79.6%

jackson-databind is vulnerable to deserialization of untrusted data. It is possible because untrusted class org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config) was not filtered by default from the interaction between serialization gadgets and polymorphic typing.

References