Skip to content

CVE-2018-19362 @ Maven-com.fasterxml.jackson.core:jackson-databind-2.6.7.1 #70

@scott-cx

Description

@scott-cx

Vulnerable Package issue exists @ Maven-com.fasterxml.jackson.core:jackson-databind-2.6.7.1 in branch main

FasterXML jackson-databind before 2.6.7.3, 2.7.x before 2.7.9.5, 2.8.x before 2.8.11.3 and 2.9.x before 2.9.8, might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.

Namespace: scott-cx
Repository: edgemere
Repository Url: https://github.com/scott-cx/edgemere
CxAST-Project: scott-cx/edgemere
CxAST platform scan: 45abb8d9-377e-427c-92f9-26a15742bad7
Branch: main
Application: edgemere
Severity: HIGH
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-502


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: HIGH
Availability impact: HIGH
Remediation Upgrade Recommendation: 2.6.7.5


References
Release Note
Issue
Commit

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions