Search the MergeBase vulnerability database for information on known vulnerabilities in open-source components.
git clone https://github.com/FasterXML/jackson-databind.git git log -p --first-parent jackson-databind-2.9.6..jackson-databind-2.9.7 -- src/main + // [databind#2097]: some 3rd party, one JDK-bundled + s.add("org.slf4j.ext.EventData"); + s.add("flex.messaging.util.concurrent.AsynchBeansWorkManagerExecutor"); + s.add("com.sun.deploy.security.ruleset.DRSHelper"); + s.add("org.apache.axis2.jaxws.spi.handler.HandlerResolverImpl"); +
Jackson-databind probably has more CVEs than any other open source Java library on the planet. But that is a bit misleading, because the CVE's tend to be associated with blacklist "gadget" entries added to jackson-databind's list of Java objects it will refuse to deserialize against. A good blog post at cowtowncoder.medium.com explains this in more detail.
Stay on top of the real risk of open source at any time.
Avoid false positives and get sophisticated upgrade guidance based on risk, compatibility, and popularity.
More on Continuous ProtectionDetect and defend against known-vulnerabilities at runtime. The only SCA to do so.
The quickest way to respond to an imminent threat like log4j with CVE-2021-44228.
More on RuntimeMergeBase directly integrates with Github and Bitbucket to provide an early warning system for your in-house development
Product Overview