Deserialization of Untrusted Data in jackson-databind
High severity
GitHub Reviewed
Published
Jun 15, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Withdrawn
This advisory was withdrawn on Jun 16, 2020
Package
Affected versions
>= 2.7.0, <= 2.7.9.3
>= 2.8.0, <= 2.8.11.1
>= 2.9.0, < 2.9.6
Patched versions
2.7.9.4
2.8.11.2
2.9.6
Description
Reviewed
Jun 11, 2020
Published to the GitHub Advisory Database
Jun 15, 2020
Withdrawn
Jun 16, 2020
Last updated
Jan 9, 2023
Withdrawn: Duplicate of GHSA-cjjf-94ff-43w7
References