First published: Thu May 21 2020(Updated: )
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jodd Jodd | <5.0.4 | |
Apache Hive | =3.1.2 | |
maven/org.jodd:jodd-json | <5.0.4 | 5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-21234.
The severity of CVE-2018-21234 is critical with a CVSS score of 9.8.
Jodd before version 5.0.4 and Apache Hive version 3.1.2 are affected by CVE-2018-21234.
CVE-2018-21234 allows for Deserialization of Untrusted JSON Data when setClassMetadataName is set in Jodd before version 5.0.4.
To fix CVE-2018-21234 in Jodd, update to version 5.0.4 or later.