CVE-2020-14195

Severity
8.1HIGH
EPSS
9.5%
top 7.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 16
Latest updateJul 15

Description

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages14 packages

NVDfasterxml/jackson-databind2.9.02.9.10.5
Debianjackson-databind< 2.11.1-1+3

Also affects: Debian Linux 8.0

🔴Vulnerability Details

4
GHSA
Deserialization of untrusted data in Jackson Databind2020-06-18
OSV
Deserialization of untrusted data in Jackson Databind2020-06-18
OSV
CVE-2020-14195: FasterXML jackson-databind 22020-06-16
CVEList
CVE-2020-14195: FasterXML jackson-databind 22020-06-16

📋Vendor Advisories

7
Oracle
Oracle Oracle Communications Applications Risk Matrix: Managing Messages (jackson-databind) — CVE-2020-141952021-07-15
Oracle
Oracle Oracle Siebel CRM Risk Matrix: EAI (jackson-databind) — CVE-2020-141952021-04-15
Ubuntu
Jackson Databind vulnerabilities2021-03-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: REST API (jackson-databind) — CVE-2020-141952021-01-15
Oracle
Oracle Oracle Communications Risk Matrix: IDIH (jackson-databind) — CVE-2020-141952020-10-15

💬Community

2
Bugzilla
CVE-2020-14195 jackson-databind: serialization in org.jsecurity.realm.jndi.JndiRealmFactory2020-06-19
Bugzilla
CVE-2020-14195 jackson-databind: mishandling of interaction between serialization gadgets and typing [fedora-all]2020-06-19