VYPR
High severity8.1NVD Advisory· Published Dec 27, 2020· Updated Apr 29, 2026

CVE-2020-35728

CVE-2020-35728

Description

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.fasterxml.jackson.core:jackson-databindMaven
>= 2.0.0, < 2.9.10.82.9.10.8

Affected products

62

Patches

2
7ae9214c0670

[maven-release-plugin] prepare release jackson-databind-2.9.10.8

https://github.com/FasterXML/jackson-databindTatu SalorantaJan 6, 2021via osv
1 file changed · +2 2
  • pom.xml+2 2 modified
    @@ -10,7 +10,7 @@
     
       <groupId>com.fasterxml.jackson.core</groupId>
       <artifactId>jackson-databind</artifactId>
    -  <version>2.9.10.8-SNAPSHOT</version>
    +  <version>2.9.10.8</version>
       <name>jackson-databind</name>
       <packaging>bundle</packaging>
       <description>General data-binding functionality for Jackson: works on core streaming API</description>
    @@ -21,7 +21,7 @@
         <connection>scm:git:git@github.com:FasterXML/jackson-databind.git</connection>
         <developerConnection>scm:git:git@github.com:FasterXML/jackson-databind.git</developerConnection>
         <url>http://github.com/FasterXML/jackson-databind</url>
    -    <tag>HEAD</tag>
    +    <tag>jackson-databind-2.9.10.8</tag>
       </scm>
     
       <properties>
    
1ca0388c2fb3

Fixed #2999

https://github.com/FasterXML/jackson-databindTatu SalorantaDec 26, 2020via ghsa
2 files changed · +6 0
  • release-notes/VERSION-2.x+2 0 modified
    @@ -14,6 +14,8 @@ Project: jackson-databind
      (reported by Al1ex@knownsec)
     #2998: Block 2 more gadget types (org.apache.tomcat/tomcat-dbcp)
      (reported by Al1ex@knownsec)
    +#2999: Block 1 more gadget type (org.glassfish.web/javax.servlet.jsp.jstl)
    + (reported by bu5yer of Sangfor FarSight Security Lab)
     
     2.9.10.7 (02-Dec-2020)
     
    
  • src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java+4 0 modified
    @@ -226,6 +226,10 @@ public class SubTypeValidator
             s.add("org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource");
             s.add("org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource");
     
    +        // [databind#2999]: org.glassfish.web/javax.servlet.jsp.jstl (embedded Xalan)
    +        // (derivative of #2469)
    +        s.add("com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool");
    +
             DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s);
         }
     
    

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

15

News mentions

0

No linked articles in our index yet.