CVE-2018-14721
Server-Side Request Forgery (SSRF) in jackson-databind
Description
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
Base CVSS
10
EPSS Score
9.9%
Introduced Version
2.0.0-RC1
Fix Available
2.8.11.3,2.9.7,2.7.9.5,2.6.7.2
Available Patches
Package
CVEs Fixed
Lines of Code Changed