VDB
EN
HIGH

GHSA-qmqc-x3r4-6v39

Polymorphic deserialization of malicious object in jackson-databind

빠른 조치

GHSA-qmqc-x3r4-6v39 — com.fasterxml.jackson.core:jackson-databind: 아래 명령으로 수정 버전으로 올리세요.

# pom.xml: bump <version>2.9.10</version> for com.fasterxml.jackson.core:jackson-databind

상세

A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Maven / com.fasterxml.jackson.core:jackson-databind
최초 영향 버전: 2.9.0 수정 버전: 2.9.10
수정 # pom.xml: bump <version>2.9.10</version> for com.fasterxml.jackson.core:jackson-databind

참고