Mmastodon TechnologyCybersecurity first seen 22 h ago, last 22 h ago, peak #11
Jackson-databind vulnerability alert resurfaces
Original: π¨ EUVD-2019-0173 π Score: n/a π Published: 2019-01-02 | Updated: 2026-10-08 π FasterXML jackson-databind 2.x before 2.9.
A security advisory, EUVD-2019-0173, warns that FasterXML jackson-databind 2.x before 2.9.7 may allow remote attackers to execute arbitrary code. The flaw stems from a failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization. Administrators running affected versions are advised to upgrade to 2.9.7 or later. The advisory, originally published in January 2019, has recently been updated, drawing renewed attention to the widely used Java library.
Why now: The advisory was recently updated, prompting automated security feeds to republish the warning about a known remote code execution flaw.
FasterXMLjackson-databindEUVD-2019-0173blaze-ds
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1535383