Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8091
HistoryDec 28, 2018 - 5:45 a.m.

Deserialization Of Untrusted Data

2018-12-2805:45:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.571 Medium

EPSS

Percentile

97.7%

jackson-databind can deserialize untrusted data. The vulnerability is due to an incomplete fix for the CVE-2017-7525.

References