Package
flyway
Component
jackson-databind
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable jackson-databind 2.18.9 is a shaded copy bundled inside the databricks-jdbc driver jar, relocated under com/databricks/internal/fasterxml/jackson, so it cannot be upgraded independently of the driver. databricks-jdbc 3.4.3 is the latest upstream release and still bundles jackson-databind 2.18.9. Remediation requires an upstream databricks-jdbc release built against jackson-databind 2.18.10 or later.
Status