
CVE-2020-35490
- Reference to the description:
- Description:
- FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
- Last updated date:
- 09/08/2022
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 07/20/2021
- Reference url to background