Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22908
HistoryApr 01, 2020 - 8:43 a.m.

Remote Code Execution

2020-04-0108:43:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.008

Percentile

81.6%

jackson-databind is vulnerable to remote code execution. The vulnerability exists as deserialization of untrusted data containing the class org.apache.commons.proxy.provider.remoting.RmiProvider was not filtered by default from the interaction between serialization gadgets and polymorphinc typing, allowing the execution of arbitrary code.