-
Notifications
You must be signed in to change notification settings - Fork 0
Description
Vulnerable Package issue exists @ Maven-com.fasterxml.jackson.core:jackson-databind-2.6.7.1 in branch main
FasterXML jackson-databind before 2.6.7.3, 2.7.x before 2.7.9.5, 2.8.x before 2.8.11.3 and 2.9.x before 2.9.8, might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
Namespace: scott-cx
Repository: edgemere
Repository Url: https://github.com/scott-cx/edgemere
CxAST-Project: scott-cx/edgemere
CxAST platform scan: 45abb8d9-377e-427c-92f9-26a15742bad7
Branch: main
Application: edgemere
Severity: HIGH
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-502
Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: HIGH
Availability impact: HIGH
Remediation Upgrade Recommendation: 2.6.7.5
References
Release Note
Issue
Commit