Search CVE reports


Toggle filters

51 – 60 of 87 results


CVE-2020-10673

Medium priority

Some fixes available 1 of 4

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-10672

Low priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2019-14893

Medium priority
Vulnerable

A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction...

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2019-14892

Medium priority
Vulnerable

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could...

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-9548

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-9547

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-9546

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-8840

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2019-20330

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2019-17531

Medium priority

Some fixes available 1 of 5

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has...

1 affected package

jackson-databind

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected Needs evaluation
Show less packages