Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 Maven

Deserialization of Untrusted Data in jackson-databind

GHSA-mx9v-gmh4-mgqw · CVE-2018-19361

Published · Modified

Description

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes