Search CVE reports


Toggle filters

41 – 50 of 87 results


CVE-2020-14060

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-14062

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-14061

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related...

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-11620

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-11619

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-11113

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-11112

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-11111

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-10969

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-10968

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages