VYPR
High severity8.1NVD Advisory· Published Jun 14, 2020· Updated Apr 29, 2026

CVE-2020-14062

CVE-2020-14062

Description

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.fasterxml.jackson.core:jackson-databindMaven
>= 2.9.0, < 2.9.10.52.9.10.5

Affected products

20

Patches

3
82c84c74e99a

[maven-release-plugin] prepare release jackson-databind-2.9.10.5

https://github.com/FasterXML/jackson-databindTatu SalorantaJun 22, 2020via osv
1 file changed · +2 2
  • pom.xml+2 2 modified
    @@ -10,7 +10,7 @@
     
       <groupId>com.fasterxml.jackson.core</groupId>
       <artifactId>jackson-databind</artifactId>
    -  <version>2.9.10.5-SNAPSHOT</version>
    +  <version>2.9.10.5</version>
       <name>jackson-databind</name>
       <packaging>bundle</packaging>
       <description>General data-binding functionality for Jackson: works on core streaming API</description>
    @@ -21,7 +21,7 @@
         <connection>scm:git:git@github.com:FasterXML/jackson-databind.git</connection>
         <developerConnection>scm:git:git@github.com:FasterXML/jackson-databind.git</developerConnection>
         <url>http://github.com/FasterXML/jackson-databind</url>
    -    <tag>HEAD</tag>
    +    <tag>jackson-databind-2.9.10.5</tag>
       </scm>
     
       <properties>
    
840eae2ca81c

... actual #2704 fix here (forgot to commit change)

https://github.com/FasterXML/jackson-databindTatu SalorantaMay 2, 2020via ghsa
1 file changed · +3 1
  • src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java+3 1 modified
    @@ -113,8 +113,10 @@ public class SubTypeValidator
             s.add("org.apache.commons.configuration.JNDIConfiguration");
             s.add("org.apache.commons.configuration2.JNDIConfiguration");
     
    -        // [databind#2469]: xalan2
    +        // [databind#2469]: xalan
             s.add("org.apache.xalan.lib.sql.JNDIConnectionPool");
    +        // [databind#2704]: xalan2
    +        s.add("com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool");
     
             // [databind#2478]: comons-dbcp, p6spy
             s.add("org.apache.commons.dbcp.datasources.PerUserPoolDataSource");
    
99001cdb6807

Fix #2704

https://github.com/FasterXML/jackson-databindTatu SalorantaMay 2, 2020via ghsa
1 file changed · +2 0
  • release-notes/VERSION-2.x+2 0 modified
    @@ -10,6 +10,8 @@ Project: jackson-databind
      (reported by Topsec(tcc))
     #2698: Block one more gadget type (weblogic/oracle-aqjms)
      (reported by Fangrun Li)
    +#2704: Block one more gadget type (weblogic/oracle-aqjms)
    + (reported by XuYuanzhen)
     
     2.9.10.4 (11-Apr-2020)
     
    

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

16

News mentions

0

No linked articles in our index yet.