Bug#940498: jackson-databind: CVE-2019-14540 CVE-2019-16335

2019-09-29 Thread Markus Koschany
Control: tags -1 pending On Mon, 16 Sep 2019 15:14:37 +0200 Salvatore Bonaccorso wrote: > Source: jackson-databind > Version: 2.9.9.3-1 > Severity: grave > Tags: security upstream > Justification: user security hole [...] > p.s.: wondering where that will going to end ;-) Hi, I also think it

Bug#940498: jackson-databind: CVE-2019-14540 CVE-2019-16335

2019-09-16 Thread Salvatore Bonaccorso
Source: jackson-databind Version: 2.9.9.3-1 Severity: grave Tags: security upstream Justification: user security hole Hi, The following vulnerabilities were published for jackson-databind. CVE-2019-14540[0]: | A Polymorphic Typing issue was discovered in FasterXML jackson- | databind before