High severity8.1NVD Advisory· Published Jan 19, 2021· Updated Jul 24, 2026
CVE-2021-20190
CVE-2021-20190
Description
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.fasterxml.jackson.core:jackson-databindMaven | >= 2.7.0, < 2.9.10.7 | 2.9.10.7 |
com.fasterxml.jackson.core:jackson-databindMaven | < 2.6.7.5 | 2.6.7.5 |
Affected products
14- FasterXML/jackson-databinddescription
- ghsa-coords3 versionspkg:maven/com.fasterxml.jackson.core/jackson-databindpkg:bitnami/nifipkg:rpm/suse/jackson-databind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2
>= 2.7.0, < 2.9.10.7+ 2 more
- (no CPE)range: >= 2.7.0, < 2.9.10.7
- (no CPE)range: >= 1.7.0, <= 1.12.1
- (no CPE)range: < 2.10.5.1-3.3.2
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*+ 1 more
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
- cpe:2.3:a:netapp:oncommand_api_services:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:service_level_manager:-:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:commerce_experience_manager:11.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
12- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/FasterXML/jackson-databind/issues/2854nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-5949-rw7g-wx7wghsaADVISORY
- lists.apache.org/thread.html/r380e9257bacb8551ee6fcf2c59890ae9477b2c78e553fa9ea08e9d9a%40%3Ccommits.nifi.apache.org%3EnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2021/04/msg00025.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-20190ghsaADVISORY
- security.netapp.com/advisory/ntap-20210219-0008/nvdThird Party Advisory
- www.oracle.com//security-alerts/cpujul2021.htmlnvdThird Party AdvisoryWEB
- github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88ghsaWEB
- github.com/FasterXML/jackson-databind/commit/7dbf51bf78d157098074a20bd9da39bd48c18e4aghsaWEB
- lists.apache.org/thread.html/r380e9257bacb8551ee6fcf2c59890ae9477b2c78e553fa9ea08e9d9a@%3Ccommits.nifi.apache.org%3EghsaWEB
- security.netapp.com/advisory/ntap-20210219-0008ghsaWEB
News mentions
0No linked articles in our index yet.