FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jackson-databind | Fasterxml | 2.9.0 (including) | 2.9.10.4 (excluding) |
Red Hat Data Grid 7.3.7 | RedHat | jackson-databind | * |
Red Hat Decision Manager 7 | RedHat | jackson-databind | * |
Red Hat Fuse 7.7.0 | RedHat | jackson-databind | * |
Red Hat JBoss Enterprise Application Platform Continuous Delivery | RedHat | jackson-databind | * |
Red Hat Process Automation 7 | RedHat | jackson-databind | * |
Red Hat Single Sign-On 7.4.0 | RedHat | jackson-databind | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-maven35-jackson-databind-0:2.7.6-2.10.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | RedHat | rh-maven35-jackson-databind-0:2.7.6-2.10.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | RedHat | rh-maven35-jackson-databind-0:2.7.6-2.10.el7 | * |
Text-Only RHOAR | RedHat | * | |
Jackson-databind | Ubuntu | bionic | * |
Jackson-databind | Ubuntu | eoan | * |
Jackson-databind | Ubuntu | esm-apps/xenial | * |
Jackson-databind | Ubuntu | focal | * |
Jackson-databind | Ubuntu | trusty | * |
Jackson-databind | Ubuntu | trusty/esm | * |
Jackson-databind | Ubuntu | xenial | * |