Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jodd | Jodd | * | 5.0.4 (excluding) |
Jodd | Ubuntu | eoan | * |
Jodd | Ubuntu | focal | * |
Jodd | Ubuntu | groovy | * |
Jodd | Ubuntu | hirsute | * |
Jodd | Ubuntu | impish | * |
Jodd | Ubuntu | kinetic | * |
Jodd | Ubuntu | trusty | * |