A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
{ "cpes": [ "cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*" ], "severity": "High" }