CVE
CVE-2020-36186
Unsafe Deserialization in jackson-databind
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource
.
Endor Patches
Patch Name
Vulnerabilities fixed
Lines of Code Changed