A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
| Software | From | Fixed in |
|---|---|---|
| apache / nifi | 1.7.0 | 1.12.1.x |
| debian / debian_linux | 9.0 | 9.0.x |
| oracle / commerce_guided_search_and_experience_manager | 11.3.2 | 11.3.2.x |
com.fasterxml.jackson.core / jackson-databind
|
- | 2.9.10.7 |
| fasterxml / jackson-databind | - | 2.6.7.5 |
| fasterxml / jackson-databind | 2.7.0 | 2.9.10.7 |