Search CVE reports


Toggle filters

31 – 40 of 72 results


CVE-2020-11113

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-11112

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-11111

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-10969

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-10968

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-10673

Medium priority

Some fixes available 1 of 4

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-10672

Low priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2019-14893

Medium priority
Vulnerable

A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction...

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2019-14892

Medium priority
Vulnerable

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could...

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-9548

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Needs evaluation Needs evaluation
Show less packages