Search CVE reports


Toggle filters

21 – 30 of 72 results


CVE-2020-35490

Medium priority
Vulnerable

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2020-25649

Medium priority
Vulnerable

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2020-24750

Medium priority
Needs evaluation

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-24616

Low priority
Needs evaluation

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-14195

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-14060

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-14062

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-14061

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related...

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-11620

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-11619

Medium priority

Some fixes available 1 of 5

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Needs evaluation Needs evaluation
Show less packages