Serialization Vulnerability in FasterXML's Jackson Databind Product
CVE-2020-36183
8.1HIGH
What is CVE-2020-36183?
The jackson-databind library from FasterXML prior to version 2.9.10.8 is vulnerable to issues arising from interactions between serialization gadgets and data typing. This vulnerability could potentially be exploited to execute arbitrary code through crafted input. The vulnerability is specifically related to the JNDIConnectionPool class from org.docx4j.org.apache.xalan.lib.sql, highlighting security concerns when handling serialized data.
