CRITICAL (9.8)
CVSS 3.1
Source: mitre
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
Aliases:
CVE-2020-9548
GHSA-p43x-xfjf-5jhr
Published: 2020-03-02
View Complete Profile →