CVE-2020-8840: Deserialization of Untrusted Data
(updated )
FasterXML jackson-databind lacks certain xbean-reflect/JNDI
blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter
.
References
Detect and mitigate CVE-2020-8840 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →