Fasterxml Jackson-Databind vulnerabilities
78 known vulnerabilities affecting fasterxml/jackson-databind.
Total CVEs
78
CISA KEV
0
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL26HIGH44MEDIUM8
Vulnerabilities
Page 1 of 4
CVE-2020-9547P1CRITICALCVSS 9.8ExploitedPoC≥ 2.0.0, < 2.7.9.7≥ 2.8.0, < 2.8.11.6+1 more2020-03-02
CVE-2020-9547 [CRITICAL] CWE-502 CVE-2020-9547: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
nvdosv
CVE-2020-9548P1CRITICALCVSS 9.8ExploitedPoC≥ 2.0.0, < 2.7.9.7≥ 2.8.0, < 2.8.11.6+1 more2020-03-02
CVE-2020-9548 [CRITICAL] CWE-502 CVE-2020-9548: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
nvdosv
CVE-2020-10650P2HIGHCVSS 8.1Exploitedfixed in 2.9.10.4v2.10.02022-12-26
CVE-2020-10650 [HIGH] CWE-502 CVE-2020-10650: A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauth
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.
nvdosv
CVE-2017-17485P2CRITICALCVSS 9.8fixed in 2.6.7.3≥ 2.7.0, < 2.7.9.2+2 more2018-01-10
CVE-2017-17485 [CRITICAL] CWE-502 CVE-2017-17485: FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring li
nvdosv
CVE-2017-7525P2CRITICALCVSS 9.8fixed in 2.6.7.1≥ 2.7.0, < 2.7.9.1+2 more2018-02-06
CVE-2017-7525 [CRITICAL] CWE-184 CVE-2017-7525: A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
nvdosv
CVE-2018-7489P2CRITICALCVSS 9.8fixed in 2.7.9.3≥ 2.8.0, < 2.8.11.1+1 more2018-02-26
CVE-2018-7489 [CRITICAL] CVE-2018-7489: FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unaut
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if t
nvdosv
CVE-2019-14379P2CRITICALCVSS 9.8≥ 2.0.0, < 2.6.7.3≥ 2.7.0, < 2.7.9.6+2 more2019-07-29
CVE-2019-14379 [CRITICAL] CWE-1321 CVE-2019-14379: SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when eh
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
nvdosv
CVE-2018-14718P2CRITICALCVSS 9.8≥ 2.0.0, < 2.6.7.3≥ 2.7.0, < 2.7.9.5+2 more2019-01-02
CVE-2018-14718 [CRITICAL] CWE-502 CVE-2018-14718: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
nvdosv
CVE-2018-14719P2CRITICALCVSS 9.8≥ 2.0.0, < 2.6.7.3≥ 2.7.0, < 2.7.9.5+2 more2019-01-02
CVE-2018-14719 [CRITICAL] CWE-502 CVE-2018-14719: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
nvdosv
CVE-2020-8840P3CRITICALCVSS 9.8≥ 2.0.0, < 2.7.9.7≥ 2.8.0, < 2.8.11.5+1 more2020-02-10
CVE-2020-8840 [CRITICAL] CWE-502 CVE-2020-8840: FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demo
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
nvdosv
CVE-2019-12086P3HIGHCVSS 7.5≥ 2.0.0, < 2.6.7.3≥ 2.7.0, < 2.7.9.6+2 more2019-05-17
CVE-2019-12086 [HIGH] CWE-502 CVE-2019-12086: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Defau
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by th
nvdosv
CVE-2017-15095P2CRITICALCVSS 9.8≥ 2.0.0, < 2.6.7.2≥ 2.7.0, < 2.7.9.2+2 more2018-02-06
CVE-2017-15095 [CRITICAL] CWE-184 CVE-2017-15095: A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, w
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be us
nvdosv
CVE-2019-14892P2CRITICALCVSS 9.8≥ 2.0.0, < 2.6.7.3≥ 2.7.0, < 2.8.11.5+1 more2020-03-02
CVE-2019-14892 [CRITICAL] CWE-200 CVE-2019-14892: A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
nvdosv
CVE-2019-14893P3CRITICALCVSS 9.8≥ 2.8.0, < 2.8.11.5≥ 2.9.0, < 2.9.102020-03-02
CVE-2019-14893 [CRITICAL] CWE-200 CVE-2019-14893: A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLAS
nvdosv
CVE-2019-16942P3CRITICALCVSS 9.8≥ 2.0.0, < 2.6.7.3≥ 2.8.0, < 2.8.11.5+1 more2019-10-01
CVE-2019-16942 [CRITICAL] CWE-502 CVE-2019-16942: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When D
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible
nvdosv
CVE-2018-14721P3CRITICALCVSS 10.0≥ 2.6.0, < 2.6.7.2≥ 2.7.0, < 2.7.9.5+5 more2019-01-02
CVE-2018-14721 [CRITICAL] CWE-918 CVE-2018-14721: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side requ
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
nvdosv
CVE-2019-16943P3CRITICALCVSS 9.8≥ 2.0.0, < 2.6.7.3≥ 2.7.0, < 2.8.11.5+1 more2019-10-01
CVE-2019-16943 [CRITICAL] CWE-502 CVE-2019-16943: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When D
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to m
nvdosv
CVE-2019-17531P3CRITICALCVSS 9.8≥ 2.0.0, < 2.6.7.3≥ 2.7.0, < 2.8.11.5+1 more2019-10-12
CVE-2019-17531 [CRITICAL] CWE-502 CVE-2019-17531: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When D
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it i
nvdosv
CVE-2020-36179P3HIGHCVSS 8.1≥ 2.0.0, < 2.6.7.5≥ 2.7.0, < 2.9.10.82021-01-07
CVE-2020-36179 [HIGH] CWE-502 CVE-2020-36179: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
nvdosv
CVE-2018-14720P3CRITICALCVSS 9.8≥ 2.6.0, < 2.6.7.2≥ 2.7.0, < 2.7.9.5+5 more2019-01-02
CVE-2018-14720 [CRITICAL] CWE-502 CVE-2018-14720: FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XX
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
nvdosv
1 / 4Next →