Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:0243-1

Опубликовано: 29 янв. 2021
Источник: suse-cvrf

Описание

Security update for jackson-databind

This update for jackson-databind fixes the following issues:

jackson-databind was updated to 2.10.5.1:

  • #2589: DOMDeserializer: setExpandEntityReferences(false) may not prevent external entity expansion in all cases (CVE-2020-25649, bsc#1177616)
  • #2787 (partial fix): NPE after add mixin for enum
  • #2679: 'ObjectMapper.readValue('123', Void.TYPE)' throws 'should never occur'

Список пакетов

Container suse/manager/5.0/x86_64/server-attestation:latest
jackson-databind-2.10.5.1-3.3.2
Container suse/manager/5.0/x86_64/server:latest
jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP4-Manager-Server-4-3
jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP4-Manager-Server-4-3-BYOS
jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
jackson-databind-2.10.5.1-3.3.2
Image server-attestation-image
jackson-databind-2.10.5.1-3.3.2
Image server-image
jackson-databind-2.10.5.1-3.3.2
SUSE Linux Enterprise Module for Development Tools 15 SP2
jackson-databind-2.10.5.1-3.3.2

Описание

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.


Затронутые продукты
Container suse/manager/5.0/x86_64/server-attestation:latest:jackson-databind-2.10.5.1-3.3.2
Container suse/manager/5.0/x86_64/server:latest:jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:jackson-databind-2.10.5.1-3.3.2

Ссылки

Описание

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).


Затронутые продукты
Container suse/manager/5.0/x86_64/server-attestation:latest:jackson-databind-2.10.5.1-3.3.2
Container suse/manager/5.0/x86_64/server:latest:jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:jackson-databind-2.10.5.1-3.3.2

Ссылки

Описание

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.


Затронутые продукты
Container suse/manager/5.0/x86_64/server-attestation:latest:jackson-databind-2.10.5.1-3.3.2
Container suse/manager/5.0/x86_64/server:latest:jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure:jackson-databind-2.10.5.1-3.3.2
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM:jackson-databind-2.10.5.1-3.3.2

Ссылки
Уязвимость SUSE-SU-2021:0243-1