FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
[
{
"source": "https://github.com/fasterxml/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b",
"id": "CVE-2018-19362-bd36a8c3",
"deprecated": false,
"target": {
"file": "src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java"
},
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"260527257968388017783984098692293872068",
"34182504020910097536472196892843889784",
"238297481152429683020771106973433108550"
]
}
}
]