EHC ❯ Vulnerability CVE-2017-4995 & CWE: 502 BeanDeserializerFactory.class_terracotta
-
Bug
-
Status: New
-
2 Major
-
Resolution:
-
-
-
drb
-
Reporter: mg_arch
-
July 12, 2017
-
0
-
Watchers: 2
-
July 13, 2017
-
Description
Comments
Michael Grom 2017-07-12
Michael Grom 2017-07-12
Affected versions: 2.10.2 -> 2.10.4
Sorry for the inconvenience caused when creating this issue.
Peter Lynch 2017-07-13
Details on this found at https://github.com/FasterXML/jackson-databind/issues/1599
According to CWE 502 : “ The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.”