Maven package
com.fasterxml.jackson.core/jackson-databind
pkg:maven/com.fasterxml.jackson.core/jackson-databind
Vulnerabilities (68)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-24750 | — | >= 2.0, < 2.6.7.5 | 2.6.7.5 | Sep 17, 2020 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration. | ||
| CVE-2020-24616 | — | >= 2.0.0, < 2.9.10.6 | 2.9.10.6 | Aug 25, 2020 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP). | ||
| CVE-2020-14195 | — | >= 2.9.0, < 2.9.10.5 | 2.9.10.5 | Jun 16, 2020 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity). | ||
| CVE-2020-14060 | Hig | 8.1 | >= 2.9.0, < 2.9.10.5 | 2.9.10.5 | Jun 14, 2020 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill). | |
| CVE-2020-14062 | Hig | 8.1 | >= 2.9.0, < 2.9.10.5 | 2.9.10.5 | Jun 14, 2020 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2). | |
| CVE-2020-14061 | — | >= 2.9.0, < 2.9.10.5 | 2.9.10.5 | Jun 14, 2020 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnecti | ||
| CVE-2020-11619 | Hig | 8.1 | >= 2.9.0, < 2.9.10.4 | 2.9.10.4 | Apr 7, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop). | |
| CVE-2020-11620 | — | >= 2.9.0, < 2.9.10.4 | 2.9.10.4 | Apr 7, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly). | ||
| CVE-2020-11113 | Hig | 8.8 | >= 2.9.0, < 2.9.10.4 | 2.9.10.4 | Mar 31, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa). | |
| CVE-2020-11112 | Hig | 8.8 | >= 2.9.0, < 2.9.10.4 | 2.9.10.4 | Mar 31, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy). | |
| CVE-2020-11111 | — | >= 2.9.0, < 2.9.10.4 | 2.9.10.4 | Mar 31, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms). | ||
| CVE-2020-10968 | — | >= 2.9.0, < 2.9.10.4 | 2.9.10.4 | Mar 26, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy). | ||
| CVE-2020-10969 | — | >= 2.9.0, < 2.9.10.4 | 2.9.10.4 | Mar 26, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane. | ||
| CVE-2020-10672 | — | >= 2.9.0, < 2.9.10.4 | 2.9.10.4 | Mar 18, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms). | ||
| CVE-2020-10673 | — | >= 2.7.0, < 2.9.10.4 | 2.9.10.4 | Mar 18, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus). | ||
| CVE-2019-14893 | — | >= 2.9.0, < 2.9.10 | 2.9.10 | Mar 2, 2020 | A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultT | ||
| CVE-2019-14892 | — | < 2.6.7.3 | 2.6.7.3 | Mar 2, 2020 | A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code. | ||
| CVE-2020-9546 | Cri | 9.8 | >= 2.9.0, < 2.9.10.4 | 2.9.10.4 | Mar 2, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config). | |
| CVE-2020-9547 | — | >= 2.9.0, < 2.9.10.4 | 2.9.10.4 | Mar 2, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap). | ||
| CVE-2020-9548 | — | >= 2.9.0, < 2.9.10.4 | 2.9.10.4 | Mar 2, 2020 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core). |
- CVE-2020-24750Sep 17, 2020affected >= 2.0, < 2.6.7.5fixed 2.6.7.5
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
- CVE-2020-24616Aug 25, 2020affected >= 2.0.0, < 2.9.10.6fixed 2.9.10.6
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
- CVE-2020-14195Jun 16, 2020affected >= 2.9.0, < 2.9.10.5fixed 2.9.10.5
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
- affected >= 2.9.0, < 2.9.10.5fixed 2.9.10.5
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).
- affected >= 2.9.0, < 2.9.10.5fixed 2.9.10.5
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).
- CVE-2020-14061Jun 14, 2020affected >= 2.9.0, < 2.9.10.5fixed 2.9.10.5
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnecti
- affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
- CVE-2020-11620Apr 7, 2020affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
- affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
- affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
- CVE-2020-11111Mar 31, 2020affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
- CVE-2020-10968Mar 26, 2020affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
- CVE-2020-10969Mar 26, 2020affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
- CVE-2020-10672Mar 18, 2020affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
- CVE-2020-10673Mar 18, 2020affected >= 2.7.0, < 2.9.10.4fixed 2.9.10.4
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
- CVE-2019-14893Mar 2, 2020affected >= 2.9.0, < 2.9.10fixed 2.9.10
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultT
- CVE-2019-14892Mar 2, 2020affected < 2.6.7.3fixed 2.6.7.3
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
- affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
- CVE-2020-9547Mar 2, 2020affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
- CVE-2020-9548Mar 2, 2020affected >= 2.9.0, < 2.9.10.4fixed 2.9.10.4
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
Page 2 of 4