Search CVE reports
61 – 70 of 72 results
Some fixes available 15 of 17
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
1 affected package
jackson-databind
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| jackson-databind | Fixed | Fixed | Fixed | Not affected |
Some fixes available 15 of 17
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
1 affected package
jackson-databind
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| jackson-databind | Fixed | Fixed | Fixed | Not affected |
Some fixes available 1 of 3
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
1 affected package
jackson-databind
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| jackson-databind | Not affected | Not affected | Not affected | Not affected |
Some fixes available 1 of 3
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
1 affected package
jackson-databind
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| jackson-databind | Not affected | Not affected | Not affected | Not affected |
Some fixes available 1 of 3
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
1 affected package
jackson-databind
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| jackson-databind | Not affected | Not affected | Not affected | Not affected |
Some fixes available 1 of 3
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
1 affected package
jackson-databind
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| jackson-databind | Not affected | Not affected | Not affected | Not affected |
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim...
1 affected package
jackson-databind
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| jackson-databind | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by...
1 affected package
jackson-databind
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| jackson-databind | — | Not affected | Not affected | Not affected |
Some fixes available 6 of 10
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the...
2 affected packages
jackson-databind, libjackson-json-java
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| jackson-databind | Not affected | Not affected | Not affected | Not affected |
| libjackson-json-java | Not affected | Not affected | Needs evaluation | Needs evaluation |
Some fixes available 6 of 9
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue...
2 affected packages
jackson-databind, libjackson-json-java
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| jackson-databind | Not affected | Not affected | Not affected | Not affected |
| libjackson-json-java | Not affected | Not affected | Needs evaluation | Needs evaluation |