An open API service providing security vulnerability metadata for many open source software ecosystems.

MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpyZzMtcXE5OS0zNWc3

Critical EPSS: 0.25246% (0.95739 Percentile) EPSS:

Deserialization of Untrusted Data in Jodd

Affected Packages Affected Versions Fixed Versions
maven:org.jodd:jodd-json < 5.0.4 5.0.4
33 Dependent packages
53 Dependent repositories

Affected Version Ranges

All affected versions

3.6.1, 3.6.2, 3.6.2-BETA1, 3.6.3, 3.6.4, 3.6.4-liferay, 3.6.5, 3.6.5-BETA1, 3.6.6, 3.6.7, 3.6.8, 3.7.1, 3.8.0, 3.8.1, 3.8.5, 3.8.6, 3.9.1, 4.0.0, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.5, 4.2.0, 4.3.0, 4.3.1, 4.3.2, 5.0.0, 5.0.1, 5.0.2, 5.0.3

All unaffected versions

5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.1.0, 5.1.2, 5.1.3, 5.1.4, 5.1.5, 5.1.6, 6.0.0, 6.0.1, 6.0.2, 6.0.3

Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.

References: