#VU17778 Input validation error in jackson-databind - CVE-2018-14719
Published: February 19, 2019
jackson-databind
FasterXML
Description
The disclosed vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to fail to block blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization. A remote attacker can send a specially crafted request that submits malicious input to execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.