Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28939
HistoryJan 08, 2021 - 7:27 a.m.

Arbitrary Code Execution

2021-01-0807:27:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

0.003 Low

EPSS

Percentile

66.1%

jackson-databind is vulnerable to remote code execution (RCE). The vulnerability exists through the lack of sanitization of the com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource class through deserialization.