CVE-2020-14379
published 2022-08-16CVE-2020-14379: A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and information…
PriorityP421medium5.6CVSS 3.1
AVLACLPRHUINSUCLILAH
EPSS
0.22%
11.9th percentile
A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and information disclosure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fasterxml | jackson-databind | >= 0 < 2.4.2-3ubuntu0.1~esm2 | 2.4.2-3ubuntu0.1~esm2 |
| redhat | jboss_a-mq | — | — |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H
osv9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f2jp-gmm4-wp64: A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and infor
ghsa_unreviewed·2022-08-17
CVE-2020-14379 [MEDIUM] CWE-611 GHSA-f2jp-gmm4-wp64: A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and infor
A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and information disclosure.
OSV
jackson-databind vulnerabilities
osv·2021-03-15·CVSS 9.8
CVE-2018-11307 jackson-databind vulnerabilities
jackson-databind vulnerabilities
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to execute
arbitrary code or other unspecified impact. (CVE-2018-12022,
CVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,
CVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,
CVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,
CVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,
CVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,
CVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2
Red Hat
broker: XXE injection in configuration files
vendor_redhat·2021-11-04·CVSS 5.6
CVE-2020-14379 [MEDIUM] CWE-611 broker: XXE injection in configuration files
broker: XXE injection in configuration files
A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and information disclosure.
A flaw was found in broker. An XEE attack can used in Broker's configuration files, leading to DoS and information disclosure. The highest threat from the vulnerability is to system availability.
Package: broker (Red Hat AMQ Broker 7) - Will not fix
Oracle
Oracle Oracle GoldenGate Risk Matrix: Security / Application Adapters (jackson-databind, SLF4J, ZooKeeper, Apache Spark) — CVE-2019-14379
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2019-14379 [CRITICAL] Oracle Oracle GoldenGate Risk Matrix: Security / Application Adapters (jackson-databind, SLF4J, ZooKeeper, Apache Spark) — CVE-2019-14379
Oracle Oracle GoldenGate Risk Matrix: Security / Application Adapters (jackson-databind, SLF4J, ZooKeeper, Apache Spark) vulnerability
CVE: CVE-2019-14379
CVSS: 0.0
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (jackson-databind) — CVE-2019-14379
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2019-14379 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (jackson-databind) — CVE-2019-14379
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (jackson-databind) vulnerability
CVE: CVE-2019-14379
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Presence-api (jackson-databind) — CVE-2019-14379
vendor_oracle·2020-01-15·CVSS 9.8
CVE-2019-14379 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Presence-api (jackson-databind) — CVE-2019-14379
Oracle Oracle Communications Applications Risk Matrix: Presence-api (jackson-databind) vulnerability
CVE: CVE-2019-14379
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
No detection rules found.
No public exploits indexed.
2022-08-16
Published