cbcvebase.

Debian Jackson-Databind vulnerabilities

69 known vulnerabilities affecting debian/jackson-databind.

Total CVEs
69
CISA KEV
0
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL27HIGH40MEDIUM2

Vulnerabilities

Page 2 of 4
CVE-2020-35728P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-35728 [HIGH] CVE-2020-35728: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl). Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: re
debian
CVE-2018-14720P3CRITICALCVSS 9.8fixed in jackson-databind 2.9.8-1 (bookworm)2018
CVE-2018-14720 [CRITICAL] CVE-2018-14720: jackson-databind - FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct ext... FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization. Scope: local bookworm: resolved (fixed in 2.9.8-1) bullseye: resolved (fixed in 2.9.8-1) forky: resolved (fixed in 2.9.8-1) sid: resolved (fixed in 2.9.8-1
debian
CVE-2018-5968P3CRITICALCVSS 9.8fixed in jackson-databind 2.9.4-1 (bookworm)2018
CVE-2018-5968 [CRITICAL] CVE-2018-5968: jackson-databind - FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthe... FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist. Scope: local bookworm: resolved (fixed in 2.9.4-1) bullseye: resolved (fixed in 2.
debian
CVE-2019-12384P3MEDIUMCVSS 5.9fixed in jackson-databind 2.9.8-3 (bookworm)2019
CVE-2019-12384 [MEDIUM] CVE-2019-12384: jackson-databind - FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a va... FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible. Scope: local bookworm: resolved (fixed in 2.9.8-3) bullseye: resolved (fixed in 2.9.8-3) forky: r
debian
CVE-2019-14540P3CRITICALCVSS 9.8fixed in jackson-databind 2.10.0-1 (bookworm)2019
CVE-2019-14540 [CRITICAL] CVE-2019-14540: jackson-databind - A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2... A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig. Scope: local bookworm: resolved (fixed in 2.10.0-1) bullseye: resolved (fixed in 2.10.0-1) forky: resolved (fixed in 2.10.0-1) sid: resolved (fixed in 2.10.0-1) trixie: resolved (fixed in 2.10.0-1)
debian
CVE-2019-20330P3CRITICALCVSS 9.8fixed in jackson-databind 2.10.1-1 (bookworm)2019
CVE-2019-20330 [CRITICAL] CVE-2019-20330: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache bloc... FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. Scope: local bookworm: resolved (fixed in 2.10.1-1) bullseye: resolved (fixed in 2.10.1-1) forky: resolved (fixed in 2.10.1-1) sid: resolved (fixed in 2.10.1-1) trixie: resolved (fixed in 2.10.1-1)
debian
CVE-2018-11307P3CRITICALCVSS 9.8fixed in jackson-databind 2.9.8-1 (bookworm)2018
CVE-2018-11307 [CRITICAL] CVE-2018-11307: jackson-databind - An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use o... An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6. Scope: local bookworm: resolved (fixed in 2.9.8-1) bullseye: resolved (fixed in 2.9.8-1) forky: resolved (fixed in 2.9.8-1) sid: resolved (fi
debian
CVE-2018-19362P3CRITICALCVSS 9.8fixed in jackson-databind 2.9.8-1 (bookworm)2018
CVE-2018-19362 [CRITICAL] CVE-2018-19362: jackson-databind - FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspec... FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization. Scope: local bookworm: resolved (fixed in 2.9.8-1) bullseye: resolved (fixed in 2.9.8-1) forky: resolved (fixed in 2.9.8-1) sid: resolved (fixed in 2.9.8-1) trixie: reso
debian
CVE-2018-19361P3CRITICALCVSS 9.8fixed in jackson-databind 2.9.8-1 (bookworm)2018
CVE-2018-19361 [CRITICAL] CVE-2018-19361: jackson-databind - FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspec... FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization. Scope: local bookworm: resolved (fixed in 2.9.8-1) bullseye: resolved (fixed in 2.9.8-1) forky: resolved (fixed in 2.9.8-1) sid: resolved (fixed in 2.9.8-1) trixie: resolved (fixe
debian
CVE-2018-19360P3CRITICALCVSS 9.8fixed in jackson-databind 2.9.8-1 (bookworm)2018
CVE-2018-19360 [CRITICAL] CVE-2018-19360: jackson-databind - FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspec... FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization. Scope: local bookworm: resolved (fixed in 2.9.8-1) bullseye: resolved (fixed in 2.9.8-1) forky: resolved (fixed in 2.9.8-1) sid: resolved (fixed in 2.9.8-1) trixie: re
debian
CVE-2021-20190P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2021
CVE-2021-20190 [HIGH] CVE-2021-20190: jackson-databind - A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the i... A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fi
debian
CVE-2018-12023P3HIGHCVSS 7.5fixed in jackson-databind 2.9.8-1 (bookworm)2018
CVE-2018-12023 [HIGH] CVE-2018-12023: jackson-databind - An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2... An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload. Scope: local boo
debian
CVE-2020-36188P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-36188 [HIGH] CVE-2020-36188: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.12.1-1) tr
debian
CVE-2018-12022P3HIGHCVSS 7.5fixed in jackson-databind 2.9.8-1 (bookworm)2018
CVE-2018-12022 [HIGH] CVE-2018-12022: jackson-databind - An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2... An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service exec
debian
CVE-2020-36184P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-36184 [HIGH] CVE-2020-36184: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.12.1-1) trixie:
debian
CVE-2020-35491P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-35491 [HIGH] CVE-2020-35491: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.12.1-1) trixie: reso
debian
CVE-2019-16335P3CRITICALCVSS 9.8fixed in jackson-databind 2.10.0-1 (bookworm)2019
CVE-2019-16335 [CRITICAL] CVE-2019-16335: jackson-databind - A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2... A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540. Scope: local bookworm: resolved (fixed in 2.10.0-1) bullseye: resolved (fixed in 2.10.0-1) forky: resolved (fixed in 2.10.0-1) sid: resolved (fixed in 2.10.0-1)
debian
CVE-2019-17267P3CRITICALCVSS 9.8fixed in jackson-databind 2.10.0-1 (bookworm)2019
CVE-2019-17267 [CRITICAL] CVE-2019-17267: jackson-databind - A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2... A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup. Scope: local bookworm: resolved (fixed in 2.10.0-1) bullseye: resolved (fixed in 2.10.0-1) forky: resolved (fixed in 2.10.0-1) sid: resolved (fixed in 2.10.0-1) trixie: resolved (fixed in 2.
debian
CVE-2020-14060P3HIGHCVSS 8.1fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-14060 [HIGH] CVE-2020-14060: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill). Scope: local bookworm: resolved (fixed in 2.11.1-1) bullseye: resolved (fixed in 2.11.1-1) forky: resolved (fixed in 2.11.1-1) sid: resolved (fixed in 2.11.1-1) tr
debian
CVE-2020-24616P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-24616 [HIGH] CVE-2020-24616: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP). Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.12.1-1) trixie: r
debian
Debian Jackson-Databind vulnerabilities | cvebase