Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8090
HistoryDec 28, 2018 - 4:02 a.m.

Deserialization Of Untrusted Data

2018-12-2804:02:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.571 Medium

EPSS

Percentile

97.7%

jackson-databind is susceptible to deserialization of untrusted data. It is due to an incomplete fix for the CVE-2017-7525 which has classes which perform general-purpose data-binding functionality and tree-model for untrusted data.

References