Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22905
HistoryApr 01, 2020 - 4:23 a.m.

Remote Code Execution (RCE)

2020-04-0104:23:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.008 Low

EPSS

Percentile

81.5%

jackson-databind is vulnerable to deserialization of untrusted data that can lead to remote code execution. It is possible because the untrusted class org.apache.openjpa.ee.WASRegistryManagedRuntime was not filtered by default from the interaction between serialization gadgets and polymorphinc typing.