Similar to other Unbounded Polymorphic Type (default typing, usually) vulnerabilities, one was reported against CXF JAX-RS implementation. Details to be added once specific class added to deny-list.
See https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 for description of the general problem.
Fixed in:
- 2.9.10
- 2.8.11.5
- 2.6.7.3
- does not affect 2.10.0 and later