Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1703-1 | jackson-databind security update |
Debian DSA |
DSA-4452-1 | jackson-databind security update |
EUVD |
EUVD-2019-0378 | An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload. |
Github GHSA |
GHSA-cjjf-94ff-43w7 | jackson-databind Deserialization of Untrusted Data vulnerability |
Ubuntu USN |
USN-4813-1 | Jackson Databind vulnerabilities |
Thu, 08 Oct 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-08T21:03:25.935Z
Reserved: 2018-06-07T00:00:00.000Z
Link: CVE-2018-12022
Updated: 2024-08-05T08:24:03.619Z
Status : Modified
Published: 2019-03-21T16:00:12.310
Modified: 2026-10-08T21:17:07.740
Link: CVE-2018-12022
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN