Skip to content

jackson-databind-2.9.10.jar: 43 vulnerabilities (highest severity is: 9.8) [master] #62

Description

@renovate
📂 Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Findings

Finding Severity 🎯 CVSS Exploit Maturity EPSS Library Type Fixed in Remediation Available Reachability
CVE-2019-16942 🟣 Critical 9.8 Not Defined 5.728% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.8.11.5,2.9.10.1
CVE-2019-16943 🟣 Critical 9.8 Not Defined 4.901% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.8.11.5,2.9.10.1
CVE-2019-20330 🟣 Critical 9.8 Not Defined 8.64% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.5,2.9.10.2
CVE-2020-8840 🟣 Critical 9.8 Not Defined 26.587% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.3
CVE-2020-9546 🟣 Critical 9.8 Not Defined 4.613% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.10.3
CVE-2020-9547 🟣 Critical 9.8 Not Defined 17.757% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.6,2.9.10.4
CVE-2020-9548 🟣 Critical 9.8 Not Defined 18.345% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.6,2.9.10.4
CVE-2020-10672 🔴 High 8.8 Not Defined 3.059% jackson-databind-2.9.10.jar Direct jackson-databind-2.9.10.4
CVE-2020-10673 🔴 High 8.8 Not Defined 8.028% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.4
CVE-2020-10968 🔴 High 8.8 Not Defined 3.538% jackson-databind-2.9.10.jar Direct jackson-databind-2.9.10.4
CVE-2020-10969 🔴 High 8.8 Not Defined 3.473% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.8.11.6;com.fasterxml.jackson.core:jackson-databind:2.7.9.7
CVE-2020-11111 🔴 High 8.8 Not Defined 3.489% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.4,2.10.0
CVE-2020-11112 🔴 High 8.8 Not Defined 3.583% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.4,2.10.0
CVE-2020-11113 🔴 High 8.8 Not Defined 6.278% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.4;2.10.0
CVE-2020-36179 🔴 High 8.8 Not Defined 20.929% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2020-36180 🔴 High 8.8 Not Defined 5.041% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2020-36181 🔴 High 8.8 Not Defined 5.018% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2020-36182 🔴 High 8.8 Not Defined 5.018% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2020-36184 🔴 High 8.8 Not Defined 10.379% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2020-10650 🔴 High 8.1 Not Defined 3.328% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.4
CVE-2020-11619 🔴 High 8.1 Not Defined 3.607% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.4
CVE-2020-11620 🔴 High 8.1 Not Defined 5.64% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.4
CVE-2020-14060 🔴 High 8.1 Not Defined 8.607% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.10.0
CVE-2020-14061 🔴 High 8.1 Not Defined 4.458% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.10.0
CVE-2020-14062 🔴 High 8.1 Not Defined 8.072% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.10.0
CVE-2020-14195 🔴 High 8.1 Not Defined 4.549% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.5
CVE-2020-24616 🔴 High 8.1 Not Defined 9.422% jackson-databind-2.9.10.jar Direct 2.9.10.6
CVE-2020-24750 🔴 High 8.1 Not Defined 7.327% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.6
CVE-2020-35490 🔴 High 8.1 Not Defined 7.694% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2020-35491 🔴 High 8.1 Not Defined 9.477% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2020-35728 🔴 High 8.1 Not Defined 12.504% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2020-36183 🔴 High 8.1 Not Defined 4.89% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2020-36185 🔴 High 8.1 Not Defined 5.218% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2020-36186 🔴 High 8.1 Not Defined 5.218% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2020-36187 🔴 High 8.1 Not Defined 5.195% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2020-36188 🔴 High 8.1 Not Defined 10.911% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2020-36189 🔴 High 8.1 Not Defined 4.912% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.9.10.8
CVE-2021-20190 🔴 High 8.1 Not Defined 7.483% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind-2.9.10.7
CVE-2020-25649 🔴 High 7.5 Not Defined 17.611% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.6.7.4,2.9.10.7,2.10.5.1,2.11.0.rc1
CVE-2022-42003 🔴 High 7.5 Not Defined 2.766% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.12.7.1,2.13.4.2
CVE-2022-42004 🔴 High 7.5 Not Defined 2.766% jackson-databind-2.9.10.jar Direct com.fasterxml.jackson.core:jackson-databind:2.13.4
CVE-2026-54514 🟠 Medium 5.3 Not Defined < 1% jackson-databind-2.9.10.jar Direct https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.8
CVE-2026-54515 🟠 Medium 5.3 Not Defined < 1% jackson-databind-2.9.10.jar Direct https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4,com.fasterxml.jackson.core:jackson-databind:2.21.5,com.fasterxml.jackson.core:jackson-databind:2.22.1,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.9,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.21.5,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.22.1

Details

🟣CVE-2019-16942

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.

Publish Date: Oct 01, 2019 04:04 PM

URL: CVE-2019-16942

Threat Assessment

Exploit Maturity:Not Defined

EPSS:5.728%

Score: 9.8


Suggested Fix

Type: Upgrade version

Origin: https://osv.dev/vulnerability/GHSA-mx7p-6679-8g3q

Release Date: Oct 01, 2019 04:04 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.8.11.5,2.9.10.1

🟣CVE-2019-16943

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

Publish Date: Oct 01, 2019 04:06 PM

URL: CVE-2019-16943

Threat Assessment

Exploit Maturity:Not Defined

EPSS:4.901%

Score: 9.8


Suggested Fix

Type: Upgrade version

Origin: https://osv.dev/vulnerability/GHSA-fmmc-742q-jg75

Release Date: Oct 01, 2019 04:06 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.8.11.5,2.9.10.1

🟣CVE-2019-20330

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

Publish Date: Jan 03, 2020 03:35 AM

URL: CVE-2019-20330

Threat Assessment

Exploit Maturity:Not Defined

EPSS:8.64%

Score: 9.8


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2526

Release Date: Jan 03, 2020 03:35 AM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.5,2.9.10.2

🟣CVE-2020-8840

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.

Publish Date: Feb 10, 2020 07:41 PM

URL: CVE-2020-8840

Threat Assessment

Exploit Maturity:Not Defined

EPSS:26.587%

Score: 9.8


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2620

Release Date: Feb 10, 2020 07:41 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.3

🟣CVE-2020-9546

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).

Publish Date: Mar 02, 2020 03:59 AM

URL: CVE-2020-9546

Threat Assessment

Exploit Maturity:Not Defined

EPSS:4.613%

Score: 9.8


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546

Release Date: Mar 02, 2020 03:59 AM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.10.3

🟣CVE-2020-9547

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).

Publish Date: Mar 02, 2020 03:59 AM

URL: CVE-2020-9547

Threat Assessment

Exploit Maturity:Not Defined

EPSS:17.757%

Score: 9.8


Suggested Fix

Type: Upgrade version

Origin: https://osv.dev/vulnerability/GHSA-q93h-jc49-78gg

Release Date: Mar 02, 2020 03:59 AM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.6,2.9.10.4

🟣CVE-2020-9548

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).

Publish Date: Mar 02, 2020 03:58 AM

URL: CVE-2020-9548

Threat Assessment

Exploit Maturity:Not Defined

EPSS:18.345%

Score: 9.8


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548

Release Date: Mar 02, 2020 03:58 AM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.6,2.9.10.4

🔴CVE-2020-10672

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).

Publish Date: Mar 18, 2020 09:17 PM

URL: CVE-2020-10672

Threat Assessment

Exploit Maturity:Not Defined

EPSS:3.059%

Score: 8.8


Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2020-10672

Release Date: Mar 18, 2020 09:17 PM

Fix Resolution : jackson-databind-2.9.10.4

🔴CVE-2020-10673

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).

Publish Date: Mar 18, 2020 09:17 PM

URL: CVE-2020-10673

Threat Assessment

Exploit Maturity:Not Defined

EPSS:8.028%

Score: 8.8


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2660

Release Date: Mar 18, 2020 09:17 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4

🔴CVE-2020-10968

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).

Publish Date: Mar 26, 2020 12:43 PM

URL: CVE-2020-10968

Threat Assessment

Exploit Maturity:Not Defined

EPSS:3.538%

Score: 8.8


Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2020-10968

Release Date: Mar 26, 2020 12:43 PM

Fix Resolution : jackson-databind-2.9.10.4

🔴CVE-2020-10969

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.

Publish Date: Mar 26, 2020 12:43 PM

URL: CVE-2020-10969

Threat Assessment

Exploit Maturity:Not Defined

EPSS:3.473%

Score: 8.8


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10969

Release Date: Mar 26, 2020 12:43 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.8.11.6;com.fasterxml.jackson.core:jackson-databind:2.7.9.7

🔴CVE-2020-11111

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).

Publish Date: Mar 31, 2020 04:37 AM

URL: CVE-2020-11111

Threat Assessment

Exploit Maturity:Not Defined

EPSS:3.489%

Score: 8.8


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11113

Release Date: Mar 31, 2020 04:37 AM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4,2.10.0

🔴CVE-2020-11112

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).

Publish Date: Mar 31, 2020 04:37 AM

URL: CVE-2020-11112

Threat Assessment

Exploit Maturity:Not Defined

EPSS:3.583%

Score: 8.8


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11112

Release Date: Mar 31, 2020 04:37 AM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4,2.10.0

🔴CVE-2020-11113

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).

Publish Date: Mar 31, 2020 04:37 AM

URL: CVE-2020-11113

Threat Assessment

Exploit Maturity:Not Defined

EPSS:6.278%

Score: 8.8


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11113

Release Date: Mar 31, 2020 04:37 AM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4;2.10.0

🔴CVE-2020-36179

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.

Publish Date: Jan 06, 2021 10:30 PM

URL: CVE-2020-36179

Threat Assessment

Exploit Maturity:Not Defined

EPSS:20.929%

Score: 8.8


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3004

Release Date: Jan 06, 2021 10:30 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2020-36180

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.

Publish Date: Jan 06, 2021 10:30 PM

URL: CVE-2020-36180

Threat Assessment

Exploit Maturity:Not Defined

EPSS:5.041%

Score: 8.8


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3004

Release Date: Jan 06, 2021 10:30 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2020-36181

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.

Publish Date: Jan 06, 2021 10:29 PM

URL: CVE-2020-36181

Threat Assessment

Exploit Maturity:Not Defined

EPSS:5.018%

Score: 8.8


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3004

Release Date: Jan 06, 2021 10:29 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2020-36182

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.

Publish Date: Jan 06, 2021 10:30 PM

URL: CVE-2020-36182

Threat Assessment

Exploit Maturity:Not Defined

EPSS:5.018%

Score: 8.8


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3004

Release Date: Jan 06, 2021 10:30 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2020-36184

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.

Publish Date: Jan 06, 2021 10:30 PM

URL: CVE-2020-36184

Threat Assessment

Exploit Maturity:Not Defined

EPSS:10.379%

Score: 8.8


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2998

Release Date: Jan 06, 2021 10:30 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2020-10650

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.

Publish Date: Dec 26, 2022 12:00 AM

URL: CVE-2020-10650

Threat Assessment

Exploit Maturity:Not Defined

EPSS:3.328%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: GHSA-rpr3-cw39-3pxh

Release Date: Dec 26, 2022 12:00 AM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4

🔴CVE-2020-11619

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).

Publish Date: Apr 07, 2020 10:14 PM

URL: CVE-2020-11619

Threat Assessment

Exploit Maturity:Not Defined

EPSS:3.607%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11619

Release Date: Apr 07, 2020 10:14 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4

🔴CVE-2020-11620

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).

Publish Date: Apr 07, 2020 10:14 PM

URL: CVE-2020-11620

Threat Assessment

Exploit Maturity:Not Defined

EPSS:5.64%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11620

Release Date: Apr 07, 2020 10:14 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4

🔴CVE-2020-14060

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).

Publish Date: Jun 14, 2020 08:46 PM

URL: CVE-2020-14060

Threat Assessment

Exploit Maturity:Not Defined

EPSS:8.607%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14060

Release Date: Jun 14, 2020 08:46 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.10.0

🔴CVE-2020-14061

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms).

Publish Date: Jun 14, 2020 07:42 PM

URL: CVE-2020-14061

Threat Assessment

Exploit Maturity:Not Defined

EPSS:4.458%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14061

Release Date: Jun 14, 2020 07:42 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.10.0

🔴CVE-2020-14062

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).

Publish Date: Jun 14, 2020 07:42 PM

URL: CVE-2020-14062

Threat Assessment

Exploit Maturity:Not Defined

EPSS:8.072%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14062

Release Date: Jun 14, 2020 07:42 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.10.0

🔴CVE-2020-14195

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).

Publish Date: Jun 16, 2020 03:07 PM

URL: CVE-2020-14195

Threat Assessment

Exploit Maturity:Not Defined

EPSS:4.549%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14195

Release Date: Jun 16, 2020 03:07 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.5

🔴CVE-2020-24616

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).

Publish Date: Aug 25, 2020 05:04 PM

URL: CVE-2020-24616

Threat Assessment

Exploit Maturity:Not Defined

EPSS:9.422%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24616

Release Date: Aug 25, 2020 05:04 PM

Fix Resolution : 2.9.10.6

🔴CVE-2020-24750

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.

Publish Date: Sep 17, 2020 06:39 PM

URL: CVE-2020-24750

Threat Assessment

Exploit Maturity:Not Defined

EPSS:7.327%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24616

Release Date: Sep 17, 2020 06:39 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.6

🔴CVE-2020-35490

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.

Publish Date: Dec 17, 2020 06:43 PM

URL: CVE-2020-35490

Threat Assessment

Exploit Maturity:Not Defined

EPSS:7.694%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2986

Release Date: Dec 17, 2020 06:43 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2020-35491

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.

Publish Date: Dec 17, 2020 06:43 PM

URL: CVE-2020-35491

Threat Assessment

Exploit Maturity:Not Defined

EPSS:9.477%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2986

Release Date: Dec 17, 2020 06:43 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2020-35728

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).

Publish Date: Dec 27, 2020 04:32 AM

URL: CVE-2020-35728

Threat Assessment

Exploit Maturity:Not Defined

EPSS:12.504%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35728

Release Date: Dec 27, 2020 04:32 AM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2020-36183

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.

Publish Date: Jan 06, 2021 10:30 PM

URL: CVE-2020-36183

Threat Assessment

Exploit Maturity:Not Defined

EPSS:4.89%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3003

Release Date: Jan 06, 2021 10:30 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2020-36185

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.

Publish Date: Jan 06, 2021 10:29 PM

URL: CVE-2020-36185

Threat Assessment

Exploit Maturity:Not Defined

EPSS:5.218%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2998

Release Date: Jan 06, 2021 10:29 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2020-36186

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.

Publish Date: Jan 06, 2021 10:29 PM

URL: CVE-2020-36186

Threat Assessment

Exploit Maturity:Not Defined

EPSS:5.218%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2997

Release Date: Jan 06, 2021 10:29 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2020-36187

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.

Publish Date: Jan 06, 2021 10:29 PM

URL: CVE-2020-36187

Threat Assessment

Exploit Maturity:Not Defined

EPSS:5.195%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2997

Release Date: Jan 06, 2021 10:29 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2020-36188

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.

Publish Date: Jan 06, 2021 10:29 PM

URL: CVE-2020-36188

Threat Assessment

Exploit Maturity:Not Defined

EPSS:10.911%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2996

Release Date: Jan 06, 2021 10:29 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2020-36189

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.

Publish Date: Jan 06, 2021 10:29 PM

URL: CVE-2020-36189

Threat Assessment

Exploit Maturity:Not Defined

EPSS:4.912%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2996

Release Date: Jan 06, 2021 10:29 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8

🔴CVE-2021-20190

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Publish Date: Jan 19, 2021 04:27 PM

URL: CVE-2021-20190

Threat Assessment

Exploit Maturity:Not Defined

EPSS:7.483%

Score: 8.1


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2854

Release Date: Jan 19, 2021 04:27 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind-2.9.10.7

🔴CVE-2020-25649

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

Publish Date: Dec 03, 2020 04:16 PM

URL: CVE-2020-25649

Threat Assessment

Exploit Maturity:Not Defined

EPSS:17.611%

Score: 7.5


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2589

Release Date: Dec 03, 2020 04:16 PM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.6.7.4,2.9.10.7,2.10.5.1,2.11.0.rc1

🔴CVE-2022-42003

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.

Publish Date: Oct 02, 2022 12:00 AM

URL: CVE-2022-42003

Threat Assessment

Exploit Maturity:Not Defined

EPSS:2.766%

Score: 7.5


Suggested Fix

Type: Upgrade version

Origin: GHSA-jjjh-jjxp-wpff

Release Date: Oct 02, 2022 12:00 AM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.12.7.1,2.13.4.2

🔴CVE-2022-42004

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

Publish Date: Oct 02, 2022 12:00 AM

URL: CVE-2022-42004

Threat Assessment

Exploit Maturity:Not Defined

EPSS:2.766%

Score: 7.5


Suggested Fix

Type: Upgrade version

Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3582

Release Date: Oct 02, 2022 12:00 AM

Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.13.4

🟠CVE-2026-54514

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

Publish Date: Jun 23, 2026 08:51 PM

URL: CVE-2026-54514

Threat Assessment

Exploit Maturity:Not Defined

EPSS:< 1%

Score: 5.3


Suggested Fix

Type: Upgrade version

Origin: FasterXML/jackson-databind@1f5a103

Release Date: Jun 23, 2026 08:51 PM

Fix Resolution : https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.8

🟠CVE-2026-54515

Vulnerable Library - jackson-databind-2.9.10.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jackson-databind-2.9.10.jar (Vulnerable Library)

Vulnerability Details

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @⁠JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @⁠JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.

Publish Date: Jun 23, 2026 08:50 PM

URL: CVE-2026-54515

Threat Assessment

Exploit Maturity:Not Defined

EPSS:< 1%

Score: 5.3


Suggested Fix

Type: Upgrade version

Origin: FasterXML/jackson-databind@0e1b0b2

Release Date: Jun 23, 2026 08:50 PM

Fix Resolution : https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4,com.fasterxml.jackson.core:jackson-databind:2.21.5,com.fasterxml.jackson.core:jackson-databind:2.22.1,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.9,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.21.5,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.22.1

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions