Improper Input Validation in jackson-databind
Critical severity
GitHub Reviewed
Published
Jun 15, 2020
to the GitHub Advisory Database
•
Updated Sep 13, 2023
Package
Affected versions
>= 2.9.0, < 2.9.10
< 2.8.11.5
Patched versions
2.9.10
2.8.11.5
Description
Published by the National Vulnerability Database
Oct 7, 2019
Reviewed
Jun 11, 2020
Published to the GitHub Advisory Database
Jun 15, 2020
Last updated
Sep 13, 2023
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10 and 2.8.11.5. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
References