2.20.1
13 years ago
2 months ago
Known vulnerabilities in the com.fasterxml.jackson.core:jackson-databind package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
com.fasterxml.jackson.core:jackson-databind is a library which contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Affected versions of this package are vulnerable to Denial of Service (DoS) in the NOTE:
For this vulnerability to be exploitable the non-default How to fix Denial of Service (DoS)? Upgrade | [2.4.0,2.12.7.1)[2.13.0,2.13.4) |
com.fasterxml.jackson.core:jackson-databind is a library which contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Affected versions of this package are vulnerable to Denial of Service (DoS) in the NOTE: This vulnerability is only exploitable when the non-default How to fix Denial of Service (DoS)? Upgrade | [2.4.0,2.12.7.1)[2.13.0,2.13.4.1) |
com.fasterxml.jackson.core:jackson-databind is a library which contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Affected versions of this package are vulnerable to Denial of Service (DoS) via a large depth of nested objects. How to fix Denial of Service (DoS)? Upgrade | [,2.12.6.1)[2.13.0,2.13.2.1) |
com.fasterxml.jackson.core:jackson-databind is a library which contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Affected versions of this package are vulnerable to Denial of Service (DoS) when using JDK serialization to serialize and deserialize How to fix Denial of Service (DoS)? Upgrade | [2.13.0,2.13.1)[2.10.0.pr1,2.12.6) |