Search CVE reports


Toggle filters

51 – 60 of 72 results


CVE-2019-14361

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-14439. Reason: This candidate is a reservation duplicate of CVE-2019-14439. Notes: All CVE users should reference CVE-2019-14439 instead of this candidate....

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected
Show less packages

CVE-2019-14439

Medium priority

Some fixes available 1 of 4

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and...

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2019-14379

Medium priority

Some fixes available 1 of 4

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-11307

Medium priority

Some fixes available 1 of 3

An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected
Show less packages

CVE-2019-12384

Medium priority

Some fixes available 14 of 18

FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote...

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2019-12814

Medium priority

Some fixes available 14 of 18

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has...

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2019-12086

Medium priority

Some fixes available 14 of 18

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the...

2 affected packages

jackson-databind, jackson-jr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Fixed Fixed Fixed Vulnerable
jackson-jr Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-12023

Medium priority

Some fixes available 1 of 3

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an...

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-12022

Medium priority

Some fixes available 1 of 2

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the...

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-19362

Medium priority

Some fixes available 15 of 18

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Fixed Fixed Fixed Vulnerable
Show less packages