• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

ConsenSys / Mahuta / 642
84%
master: 84%

Build:
Build:
LAST BUILD BRANCH: dependabot/maven/com.fasterxml.jackson.core-jackson-databind-2.10.0.pr1
DEFAULT BRANCH: master
Ran 02 Jun 2019 09:02PM UTC
Jobs 1
Files 80
Run time 4s
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

pending completion
642

push

circleci

gjeanmart
moderate severity
Vulnerable versions: >= 2.0.0, < 2.9.9
Patched version: 2.9.9
A Polymorphic Typing issue was discovered in FasterXML jackson-databind
2.x before 2.9.9. When Default Typing is enabled (either globally or for
a specific property) for an externally exposed JSON endpoint, the
service has the mysql-connector-java jar (8.0.14 or earlier) in the
classpath, and an attacker can host a crafted MySQL server reachable by
the victim, an attacker can send a crafted JSON message that allows them
to read arbitrary local files on the server. This occurs because of
missing com.mysql.cj.jdbc.admin.MiniAdmin validation.

1093 of 1271 relevant lines covered (86.0%)

0.86 hits per line

Jobs
ID Job ID Ran Files Coverage
1 642.1 02 Jun 2019 09:02PM UTC 0
86.0
Source Files on build 642
Detailed source file information is not available for this build.
  • Back to Repo
  • CircleCI Build #642
  • 11fd1050 on github
  • Prev Build on development (#639)
  • Next Build on development (#645)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc