Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36386
HistoryJul 18, 2022 - 9:06 a.m.

Deserialization Of Untrusted Data

2022-07-1809:06:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.005 Low

EPSS

Percentile

75.8%

Jackson Databind is vulnerable to deserialization of untrusted data. The vulnerability exists in Set function in SubTypeValidator.java when handling interactions related to class ignite-jta which allows an attacker to inject and execute malicious codes.