Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE: 2019-16942 found in jackson-databind - Version: 2.4.2 [JAVA] #38

Open
github-actions bot opened this issue Jan 17, 2024 · 2 comments
Open

CVE: 2019-16942 found in jackson-databind - Version: 2.4.2 [JAVA] #38

github-actions bot opened this issue Jan 17, 2024 · 2 comments
Labels
Severity: High High severity Veracode Dependency Scanning A Veracode identified vulnerability

Comments

@github-actions
Copy link

Veracode Software Composition Analysis

Attribute Details
Library jackson-databind
Description General data-binding functionality for Jackson: works on core streaming API
Language JAVA
Vulnerability Remote Code Execution (RCE)
Vulnerability description jackson-databind is vulnerable to remote code execution. The vulnerability exists as it does not stop classes from the commons-dbcp package from being used as deserialization gadgets.
CVE 2019-16942
CVSS score 7.5
Vulnerability present in version/s 2.0.0-RC1-2.6.7.2
Found library version/s 2.4.2
Vulnerability fixed in version 2.6.7.3
Library latest version 2.16.1
Fix Apply the indicated patch (v2.9.10.1) instead of upgrading directly to 2.10.0. If upgrading to the next minor version, use the new safe methods for default typing and whitelisting. Refer to (FasterXML/jackson-databind#2195 (comment))

Links:

@github-actions github-actions bot added Severity: High High severity Veracode Dependency Scanning A Veracode identified vulnerability labels Jan 17, 2024
Copy link
Author

Veracode issue link to PR: #2

Copy link
Author

Veracode issue link to PR: #43

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Severity: High High severity Veracode Dependency Scanning A Veracode identified vulnerability
Projects
None yet
Development

No branches or pull requests

0 participants