FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jackson-databind | Fasterxml | 2.9.0 (including) | 2.9.10.8 (excluding) |
OpenShift Logging 5.0 | RedHat | openshift-logging/elasticsearch6-rhel8:v5.0.3-1 | * |
Red Hat OpenShift Container Platform 4.6 | RedHat | openshift4/ose-logging-elasticsearch6:v4.6.0-202104161407.p0 | * |
Jackson-databind | Ubuntu | bionic | * |
Jackson-databind | Ubuntu | devel | * |
Jackson-databind | Ubuntu | esm-apps/bionic | * |
Jackson-databind | Ubuntu | esm-apps/focal | * |
Jackson-databind | Ubuntu | esm-apps/jammy | * |
Jackson-databind | Ubuntu | esm-apps/noble | * |
Jackson-databind | Ubuntu | esm-apps/xenial | * |
Jackson-databind | Ubuntu | focal | * |
Jackson-databind | Ubuntu | groovy | * |
Jackson-databind | Ubuntu | hirsute | * |
Jackson-databind | Ubuntu | impish | * |
Jackson-databind | Ubuntu | jammy | * |
Jackson-databind | Ubuntu | kinetic | * |
Jackson-databind | Ubuntu | lunar | * |
Jackson-databind | Ubuntu | mantic | * |
Jackson-databind | Ubuntu | noble | * |
Jackson-databind | Ubuntu | oracular | * |
Jackson-databind | Ubuntu | plucky | * |
Jackson-databind | Ubuntu | trusty | * |
Jackson-databind | Ubuntu | trusty/esm | * |
Jackson-databind | Ubuntu | xenial | * |