Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Deserialization of Untrusted Data (CVE-2019-16335) #74

Closed
vdenotaris opened this issue Oct 2, 2019 · 1 comment
Closed

Deserialization of Untrusted Data (CVE-2019-16335) #74

vdenotaris opened this issue Oct 2, 2019 · 1 comment
Assignees
Labels
kind/bug Categorizes issue or pull request as related to a bug. priority/critical-urgent Highest priority. Must be actively worked on as someone's top priority right now.

Comments

@vdenotaris
Copy link
Owner

Deserialization of Untrusted Data
com.fasterxml.jackson.core:jackson-databind is a library which contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor.

Affected versions of this package are vulnerable to Deserialization of Untrusted Data. A Polymorphic Typing issue was discovered as com.zaxxer.hikari.HikariDataSource was not blocked. Note: This is a different vulnerability than CVE-2019-14540.

@vdenotaris vdenotaris added kind/bug Categorizes issue or pull request as related to a bug. priority/critical-urgent Highest priority. Must be actively worked on as someone's top priority right now. labels Oct 2, 2019
@vdenotaris vdenotaris self-assigned this Oct 2, 2019
@vdenotaris
Copy link
Owner Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug Categorizes issue or pull request as related to a bug. priority/critical-urgent Highest priority. Must be actively worked on as someone's top priority right now.
Projects
Development

No branches or pull requests

1 participant