Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22802
HistoryMar 27, 2020 - 2:14 a.m.

Deserialization Of Untrusted Object

2020-03-2702:14:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

0.008 Low

EPSS

Percentile

81.6%

jackson-databind is vulnerable to deserialization of untrusted data. It was possible for an untrusted class, javax.swing.JEditorPane to be used as a serialization gadget through polymorphic typing, potentially allowing execution of arbitrary code.