Another gadget (*) type reported related to JNDI access.
See https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 for description of the general problem.
Mitre id: CVE-2020-8840
Original discoverer: @threedr3am
Fixed in:
- 2.9.10.3 (
jackson-bom version 2.9.10.20200223)
- 2.8.11.5 (
jackson-bom version 2.8.11.20200210)
- 2.7.9.7
- does not affect 2.10.0 and later