Loading HuntDB...

GHSA-c27h-mcmw-48hv

GitHub Security Advisory

Deserialization of Untrusted Data in org.codehaus.jackson:jackson-mapper-asl

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.

Affected Packages

Maven org.codehaus.jackson:jackson-mapper-asl
Affected versions: 0 (last affected: 1.9.13)

Related CVEs

Key Information

GHSA ID
GHSA-c27h-mcmw-48hv
Published
May 24, 2022 4:57 PM
Last Modified
February 14, 2023 12:56 AM
CVSS Score
9.0 /10
Primary Ecosystem
Maven
Primary Package
org.codehaus.jackson:jackson-mapper-asl
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 18, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.