VYPR

Maven package

com.fasterxml.jackson.core/jackson-databind

pkg:maven/com.fasterxml.jackson.core/jackson-databind

Vulnerabilities (68)

  • CVE-2020-24750Sep 17, 2020
    affected >= 2.0, < 2.6.7.5fixed 2.6.7.5

    FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.

  • CVE-2020-24616Aug 25, 2020
    affected >= 2.0.0, < 2.9.10.6fixed 2.9.10.6

    FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).

  • CVE-2020-14195Jun 16, 2020
    affected >= 2.9.0, < 2.9.10.5fixed 2.9.10.5

    FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).

  • CVE-2020-14060HigJun 14, 2020
    affected >= 2.9.0, < 2.9.10.5fixed 2.9.10.5

    FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).

  • CVE-2020-14062HigJun 14, 2020
    affected >= 2.9.0, < 2.9.10.5fixed 2.9.10.5

    FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).

  • CVE-2020-14061Jun 14, 2020
    affected >= 2.9.0, < 2.9.10.5fixed 2.9.10.5

    FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnecti

  • CVE-2020-11619HigApr 7, 2020
    affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).

  • CVE-2020-11620Apr 7, 2020
    affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).

  • CVE-2020-11113HigMar 31, 2020
    affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).

  • CVE-2020-11112HigMar 31, 2020
    affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).

  • CVE-2020-11111Mar 31, 2020
    affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).

  • CVE-2020-10968Mar 26, 2020
    affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).

  • CVE-2020-10969Mar 26, 2020
    affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.

  • CVE-2020-10672Mar 18, 2020
    affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).

  • CVE-2020-10673Mar 18, 2020
    affected >= 2.7.0, < 2.9.10.4fixed 2.9.10.4

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).

  • CVE-2019-14893Mar 2, 2020
    affected >= 2.9.0, < 2.9.10fixed 2.9.10

    A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultT

  • CVE-2019-14892Mar 2, 2020
    affected < 2.6.7.3fixed 2.6.7.3

    A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.

  • CVE-2020-9546CriMar 2, 2020
    affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).

  • CVE-2020-9547Mar 2, 2020
    affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).

  • CVE-2020-9548Mar 2, 2020
    affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).