cbcvebase.

Debian Jackson-Databind vulnerabilities

69 known vulnerabilities affecting debian/jackson-databind.

Total CVEs
69
CISA KEV
0
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL27HIGH40MEDIUM2

Vulnerabilities

Page 4 of 4
CVE-2020-14195P3HIGHCVSS 8.1fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-14195 [HIGH] CVE-2020-14195: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity). Scope: local bookworm: resolved (fixed in 2.11.1-1) bullseye: resolved (fixed in 2.11.1-1) forky: resolved (fixed in 2.11.1-1) sid: resolved (fixed in 2.11.1-1) trixie:
debian
CVE-2020-11619P3HIGHCVSS 8.1fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-11619 [HIGH] CVE-2020-11619: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop). Scope: local bookworm: resolved (fixed in 2.11.1-1) bullseye: resolved (fixed in 2.11.1-1) forky: resolved (fixed in 2.11.1-1) sid: resolved (fixed in 2.11.1
debian
CVE-2019-12814P3MEDIUMCVSS 5.9fixed in jackson-databind 2.9.8-3 (bookworm)2019
CVE-2019-12814 [MEDIUM] CVE-2019-12814: jackson-databind - A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x thro... A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary
debian
CVE-2020-10968P3HIGHCVSS 8.8fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-10968 [HIGH] CVE-2020-10968: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy). Scope: local bookworm: resolved (fixed in 2.11.1-1) bullseye: resolved (fixed in 2.11.1-1) forky: resolved (fixed in 2.11.1-1) sid: resolved (fixed in 2.11.1-1) trixi
debian
CVE-2020-11111P3HIGHCVSS 8.8fixed in jackson-databind 2.11.1-1 (bookworm)2020
CVE-2020-11111 [HIGH] CVE-2020-11111: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms). Scope: local bookworm: resolved (fixed in 2.11.1-1) bullseye: resolved (fixed in 2.11.1-1) forky: resolved (fixed in 2.11.1-1) sid: resol
debian
CVE-2022-42003P3HIGHCVSS 7.5fixed in jackson-databind 2.14.0-1 (bookworm)2022
CVE-2022-42003 [HIGH] CVE-2022-42003: jackson-databind - In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource e... In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. Scope: local bookworm: resolved (fixed in 2.14.0-1) bullseye: resolved (fixed in 2.12.1-1+deb11u1) forky
debian
CVE-2020-36518P3HIGHCVSS 7.5fixed in jackson-databind 2.13.2.2-1 (bookworm)2020
CVE-2020-36518 [HIGH] CVE-2020-36518: jackson-databind - jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial ... jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. Scope: local bookworm: resolved (fixed in 2.13.2.2-1) bullseye: resolved (fixed in 2.12.1-1+deb11u1) forky: resolved (fixed in 2.13.2.2-1) sid: resolved (fixed in 2.13.2.2-1) trixie: resolved (fixed in 2.13.2.2-1)
debian
CVE-2022-42004P3HIGHCVSS 7.5fixed in jackson-databind 2.14.0-1 (bookworm)2022
CVE-2022-42004 [HIGH] CVE-2022-42004: jackson-databind - In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur becau... In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization. Scope: local bookworm: resolved (fixed in 2.14.0-1) bullseye: resolved (fixed in 2.12.
debian
CVE-2021-46877P3HIGHCVSS 7.5fixed in jackson-databind 2.13.2.2-1 (bookworm)2021
CVE-2021-46877 [HIGH] CVE-2021-46877: jackson-databind - jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 al... jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization. Scope: local bookworm: resolved (fixed in 2.13.2.2-1) bullseye: open forky: resolved (fixed in 2.13.2.2-1) sid: resolved (fixed in 2.13.2
debian
Debian Jackson-Databind vulnerabilities | cvebase