Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-20190

Опубликовано: 19 янв. 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 8.3
CVSS3: 8.1

Описание

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

2.13.2.2-1
esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

not-affected

2.13.2.2-1
esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

needs-triage

focal

ignored

end of standard support, was needs-triage
groovy

ignored

end of life

Показывать по

8.3 High

CVSS2

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
около 5 лет назад

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 8.1
nvd
около 5 лет назад

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 8.1
debian
около 5 лет назад

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishan ...

CVSS3: 8.1
github
около 5 лет назад

Deserialization of untrusted data in jackson-databind

CVSS3: 8.1
fstec
около 5 лет назад

Уязвимость библиотеки jackson-databind проекта FasterXML, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код

8.3 High

CVSS2

8.1 High

CVSS3