Details
-
Bug
-
Status: Resolved
-
Minor
-
Resolution: Won't Fix
-
2.4.7
-
None
-
None
Description
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
Spark 2.4.7 still using Jackson 2.6.7