cbcvebase.

Debian Jackson-Databind vulnerabilities

69 known vulnerabilities affecting debian/jackson-databind.

Total CVEs
69
CISA KEV
0
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL27HIGH40MEDIUM2

Vulnerabilities

Page 3 of 4
CVE-2020-14062P3HIGHCVSS 8.1fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-14062 [HIGH] CVE-2020-14062: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2). Scope: local bookworm: resolved (fixed in 2.11.1-1) bullseye: resolved (fixed in 2.11.1-1) forky: resolved (fixed in 2.11.1-1) sid: resolved (fixed in 2.11.1
debian
CVE-2020-36183P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-36183 [HIGH] CVE-2020-36183: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.12.1-1) trixie: resolve
debian
CVE-2019-14439P3HIGHCVSS 7.5fixed in jackson-databind 2.9.9.3-1 (bookworm)2019
CVE-2019-14439 [HIGH] CVE-2019-14439: jackson-databind - A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x befo... A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath. Scope: local bookworm: resolved (fixed in 2.9.9.3-1) bullseye: resolved (fixed in 2.9
debian
CVE-2020-35490P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-35490 [HIGH] CVE-2020-35490: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.12.1-1) trixie: res
debian
CVE-2020-24750P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-24750 [HIGH] CVE-2020-24750: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.12.1-1) trixie: res
debian
CVE-2020-14061P3HIGHCVSS 8.1fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-14061 [HIGH] CVE-2020-14061: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms).
debian
CVE-2020-10673P3HIGHCVSS 8.8fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-10673 [HIGH] CVE-2020-10673: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus). Scope: local bookworm: resolved (fixed in 2.11.1-1) bullseye: resolved (fixed in 2.11.1-1) forky: resolved (fixed in 2.11.1-1) sid: resolved (fixed in 2.11.1-1) trixie: resol
debian
CVE-2020-9546P3CRITICALCVSS 9.8fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-9546 [CRITICAL] CVE-2020-9546: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config). Scope: local bookworm: resolved (fixed in 2.11.1-1) bullseye: resolved (fixed in 2.11.1-1) forky: resolved (fixed in 2.11.1-1) sid: resolved (fixe
debian
CVE-2020-36185P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-36185 [HIGH] CVE-2020-36185: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.12.1-1) trixie:
debian
CVE-2020-36186P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-36186 [HIGH] CVE-2020-36186: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.12.1-1) trixie:
debian
CVE-2020-36187P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-36187 [HIGH] CVE-2020-36187: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.12.1-1) trixie: r
debian
CVE-2020-36180P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-36180 [HIGH] CVE-2020-36180: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.12.1-1) trixie: resolve
debian
CVE-2020-36182P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-36182 [HIGH] CVE-2020-36182: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.12.1-1) trixie: res
debian
CVE-2020-36181P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-36181 [HIGH] CVE-2020-36181: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.12.1-1) trixie: reso
debian
CVE-2020-36189P3HIGHCVSS 8.1fixed in jackson-databind 2.12.1-1 (bookworm)2020
CVE-2020-36189 [HIGH] CVE-2020-36189: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource. Scope: local bookworm: resolved (fixed in 2.12.1-1) bullseye: resolved (fixed in 2.12.1-1) forky: resolved (fixed in 2.12.1-1) sid: resolved (fixed in 2.1
debian
CVE-2020-11620P3HIGHCVSS 8.1fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-11620 [HIGH] CVE-2020-11620: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly). Scope: local bookworm: resolved (fixed in 2.11.1-1) bullseye: resolved (fixed in 2.11.1-1) forky: resolved (fixed in 2.11.1-1) sid: resolved (fixed in 2.11.1-1) trixie: res
debian
CVE-2020-11113P3HIGHCVSS 8.8fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-11113 [HIGH] CVE-2020-11113: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa). Scope: local bookworm: resolved (fixed in 2.11.1-1) bullseye: resolved (fixed in 2.11.1-1) forky: resolved (fixed in 2.11.1-1) sid: resolved (fixed in 2.11.1-1) trixie:
debian
CVE-2020-10969P3HIGHCVSS 8.8fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-10969 [HIGH] CVE-2020-10969: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane. Scope: local bookworm: resolved (fixed in 2.11.1-1) bullseye: resolved (fixed in 2.11.1-1) forky: resolved (fixed in 2.11.1-1) sid: resolved (fixed in 2.11.1-1) trixie: resolved (fixed in 2.11.1-1)
debian
CVE-2020-11112P3HIGHCVSS 8.8fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-11112 [HIGH] CVE-2020-11112: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy). Scope: local bookworm: resolved (fixed in 2.11.1-1) bullseye: resolved (fixed in 2.11.1-1) forky: resolved (fixed in 2.11.1-1) sid: resolved (fixed i
debian
CVE-2020-10672P3HIGHCVSS 8.8fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-10672 [HIGH] CVE-2020-10672: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms). Scope: local bookworm: resolved (fixed in 2.11.1-1) bullseye: resolved (fixed in 2.11.1-1) forky: resolved (fixed in 2.11.1-1) sid: res
debian
Debian Jackson-Databind vulnerabilities | cvebase