Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28909
HistoryJan 07, 2021 - 9:36 a.m.

Deserialization Of Untrusted Object

2021-01-0709:36:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.003 Low

EPSS

Percentile

66.1%

jackson-databind is vulnerable to deserialization of untrusted data that can lead to remote code execution. It is possible because untrusted classes org.apache.commons.dbcp2.datasources.SharedPoolDataSource was not filtered by default from the interaction between serialization gadgets and polymorphic typing.