A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://github.com/FasterXML/jackson-databind/issues/2854 | patch third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1916633 | third party advisory issue tracking patch |
https://lists.apache.org/thread.html/r380e9257bacb8551ee6fcf2c59890ae9477b2c78e553fa9ea08e9d9a%40%3Ccommits.nifi.apache.org%3E | mailing list |
https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html | mailing list third party advisory |
https://www.oracle.com//security-alerts/cpujul2021.html | third party advisory |
https://security.netapp.com/advisory/ntap-20210219-0008/ | third party advisory |