FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jackson-databind | Fasterxml | 2.0.0 (including) | 2.9.10.6 (excluding) |
Jackson-databind | Ubuntu | bionic | * |
Jackson-databind | Ubuntu | focal | * |
Jackson-databind | Ubuntu | groovy | * |
Jackson-databind | Ubuntu | hirsute | * |
Jackson-databind | Ubuntu | impish | * |
Jackson-databind | Ubuntu | kinetic | * |
Jackson-databind | Ubuntu | lunar | * |
Jackson-databind | Ubuntu | mantic | * |
Jackson-databind | Ubuntu | oracular | * |
Jackson-databind | Ubuntu | trusty | * |
Jackson-databind | Ubuntu | trusty/esm | * |
Jackson-databind | Ubuntu | xenial | * |