📂 Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Findings
| Finding |
Severity |
🎯 CVSS |
Exploit Maturity |
EPSS |
Library |
Type |
Fixed in |
Remediation Available |
Reachability |
| CVE-2019-16942 |
🟣 Critical |
9.8 |
Not Defined |
5.728% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.8.11.5,2.9.10.1 |
✅ |
|
| CVE-2019-16943 |
🟣 Critical |
9.8 |
Not Defined |
4.901% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.8.11.5,2.9.10.1 |
✅ |
|
| CVE-2019-20330 |
🟣 Critical |
9.8 |
Not Defined |
8.64% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.5,2.9.10.2 |
✅ |
|
| CVE-2020-8840 |
🟣 Critical |
9.8 |
Not Defined |
26.587% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.3 |
✅ |
|
| CVE-2020-9546 |
🟣 Critical |
9.8 |
Not Defined |
4.613% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.10.3 |
✅ |
|
| CVE-2020-9547 |
🟣 Critical |
9.8 |
Not Defined |
17.757% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.6,2.9.10.4 |
✅ |
|
| CVE-2020-9548 |
🟣 Critical |
9.8 |
Not Defined |
18.345% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.6,2.9.10.4 |
✅ |
|
| CVE-2020-10672 |
🔴 High |
8.8 |
Not Defined |
3.059% |
jackson-databind-2.9.10.jar |
Direct |
jackson-databind-2.9.10.4 |
✅ |
|
| CVE-2020-10673 |
🔴 High |
8.8 |
Not Defined |
8.028% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.4 |
✅ |
|
| CVE-2020-10968 |
🔴 High |
8.8 |
Not Defined |
3.538% |
jackson-databind-2.9.10.jar |
Direct |
jackson-databind-2.9.10.4 |
✅ |
|
| CVE-2020-10969 |
🔴 High |
8.8 |
Not Defined |
3.473% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.8.11.6;com.fasterxml.jackson.core:jackson-databind:2.7.9.7 |
✅ |
|
| CVE-2020-11111 |
🔴 High |
8.8 |
Not Defined |
3.489% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.4,2.10.0 |
✅ |
|
| CVE-2020-11112 |
🔴 High |
8.8 |
Not Defined |
3.583% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.4,2.10.0 |
✅ |
|
| CVE-2020-11113 |
🔴 High |
8.8 |
Not Defined |
6.278% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.4;2.10.0 |
✅ |
|
| CVE-2020-36179 |
🔴 High |
8.8 |
Not Defined |
20.929% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2020-36180 |
🔴 High |
8.8 |
Not Defined |
5.041% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2020-36181 |
🔴 High |
8.8 |
Not Defined |
5.018% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2020-36182 |
🔴 High |
8.8 |
Not Defined |
5.018% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2020-36184 |
🔴 High |
8.8 |
Not Defined |
10.379% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2020-10650 |
🔴 High |
8.1 |
Not Defined |
3.328% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.4 |
✅ |
|
| CVE-2020-11619 |
🔴 High |
8.1 |
Not Defined |
3.607% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.4 |
✅ |
|
| CVE-2020-11620 |
🔴 High |
8.1 |
Not Defined |
5.64% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.4 |
✅ |
|
| CVE-2020-14060 |
🔴 High |
8.1 |
Not Defined |
8.607% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.10.0 |
✅ |
|
| CVE-2020-14061 |
🔴 High |
8.1 |
Not Defined |
4.458% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.10.0 |
✅ |
|
| CVE-2020-14062 |
🔴 High |
8.1 |
Not Defined |
8.072% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.10.0 |
✅ |
|
| CVE-2020-14195 |
🔴 High |
8.1 |
Not Defined |
4.549% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.5 |
✅ |
|
| CVE-2020-24616 |
🔴 High |
8.1 |
Not Defined |
9.422% |
jackson-databind-2.9.10.jar |
Direct |
2.9.10.6 |
✅ |
|
| CVE-2020-24750 |
🔴 High |
8.1 |
Not Defined |
7.327% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.6 |
✅ |
|
| CVE-2020-35490 |
🔴 High |
8.1 |
Not Defined |
7.694% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2020-35491 |
🔴 High |
8.1 |
Not Defined |
9.477% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2020-35728 |
🔴 High |
8.1 |
Not Defined |
12.504% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2020-36183 |
🔴 High |
8.1 |
Not Defined |
4.89% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2020-36185 |
🔴 High |
8.1 |
Not Defined |
5.218% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2020-36186 |
🔴 High |
8.1 |
Not Defined |
5.218% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2020-36187 |
🔴 High |
8.1 |
Not Defined |
5.195% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2020-36188 |
🔴 High |
8.1 |
Not Defined |
10.911% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2020-36189 |
🔴 High |
8.1 |
Not Defined |
4.912% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.9.10.8 |
✅ |
|
| CVE-2021-20190 |
🔴 High |
8.1 |
Not Defined |
7.483% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind-2.9.10.7 |
✅ |
|
| CVE-2020-25649 |
🔴 High |
7.5 |
Not Defined |
17.611% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.6.7.4,2.9.10.7,2.10.5.1,2.11.0.rc1 |
✅ |
|
| CVE-2022-42003 |
🔴 High |
7.5 |
Not Defined |
2.766% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.12.7.1,2.13.4.2 |
✅ |
|
| CVE-2022-42004 |
🔴 High |
7.5 |
Not Defined |
2.766% |
jackson-databind-2.9.10.jar |
Direct |
com.fasterxml.jackson.core:jackson-databind:2.13.4 |
✅ |
|
| CVE-2026-54514 |
🟠 Medium |
5.3 |
Not Defined |
< 1% |
jackson-databind-2.9.10.jar |
Direct |
https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.8 |
✅ |
|
| CVE-2026-54515 |
🟠 Medium |
5.3 |
Not Defined |
< 1% |
jackson-databind-2.9.10.jar |
Direct |
https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4,com.fasterxml.jackson.core:jackson-databind:2.21.5,com.fasterxml.jackson.core:jackson-databind:2.22.1,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.9,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.21.5,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.22.1 |
✅ |
|
Details
🟣CVE-2019-16942
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.
Publish Date: Oct 01, 2019 04:04 PM
URL: CVE-2019-16942
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.728%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://osv.dev/vulnerability/GHSA-mx7p-6679-8g3q
Release Date: Oct 01, 2019 04:04 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.8.11.5,2.9.10.1
🟣CVE-2019-16943
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.
Publish Date: Oct 01, 2019 04:06 PM
URL: CVE-2019-16943
Threat Assessment
Exploit Maturity:Not Defined
EPSS:4.901%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://osv.dev/vulnerability/GHSA-fmmc-742q-jg75
Release Date: Oct 01, 2019 04:06 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.8.11.5,2.9.10.1
🟣CVE-2019-20330
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
Publish Date: Jan 03, 2020 03:35 AM
URL: CVE-2019-20330
Threat Assessment
Exploit Maturity:Not Defined
EPSS:8.64%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2526
Release Date: Jan 03, 2020 03:35 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.5,2.9.10.2
🟣CVE-2020-8840
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
Publish Date: Feb 10, 2020 07:41 PM
URL: CVE-2020-8840
Threat Assessment
Exploit Maturity:Not Defined
EPSS:26.587%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2620
Release Date: Feb 10, 2020 07:41 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.3
🟣CVE-2020-9546
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
Publish Date: Mar 02, 2020 03:59 AM
URL: CVE-2020-9546
Threat Assessment
Exploit Maturity:Not Defined
EPSS:4.613%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546
Release Date: Mar 02, 2020 03:59 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.10.3
🟣CVE-2020-9547
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
Publish Date: Mar 02, 2020 03:59 AM
URL: CVE-2020-9547
Threat Assessment
Exploit Maturity:Not Defined
EPSS:17.757%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://osv.dev/vulnerability/GHSA-q93h-jc49-78gg
Release Date: Mar 02, 2020 03:59 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.6,2.9.10.4
🟣CVE-2020-9548
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
Publish Date: Mar 02, 2020 03:58 AM
URL: CVE-2020-9548
Threat Assessment
Exploit Maturity:Not Defined
EPSS:18.345%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548
Release Date: Mar 02, 2020 03:58 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.6,2.9.10.4
🔴CVE-2020-10672
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
Publish Date: Mar 18, 2020 09:17 PM
URL: CVE-2020-10672
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.059%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2020-10672
Release Date: Mar 18, 2020 09:17 PM
Fix Resolution : jackson-databind-2.9.10.4
🔴CVE-2020-10673
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
Publish Date: Mar 18, 2020 09:17 PM
URL: CVE-2020-10673
Threat Assessment
Exploit Maturity:Not Defined
EPSS:8.028%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2660
Release Date: Mar 18, 2020 09:17 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4
🔴CVE-2020-10968
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
Publish Date: Mar 26, 2020 12:43 PM
URL: CVE-2020-10968
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.538%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2020-10968
Release Date: Mar 26, 2020 12:43 PM
Fix Resolution : jackson-databind-2.9.10.4
🔴CVE-2020-10969
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
Publish Date: Mar 26, 2020 12:43 PM
URL: CVE-2020-10969
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.473%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10969
Release Date: Mar 26, 2020 12:43 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.8.11.6;com.fasterxml.jackson.core:jackson-databind:2.7.9.7
🔴CVE-2020-11111
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
Publish Date: Mar 31, 2020 04:37 AM
URL: CVE-2020-11111
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.489%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11113
Release Date: Mar 31, 2020 04:37 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4,2.10.0
🔴CVE-2020-11112
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
Publish Date: Mar 31, 2020 04:37 AM
URL: CVE-2020-11112
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.583%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11112
Release Date: Mar 31, 2020 04:37 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4,2.10.0
🔴CVE-2020-11113
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
Publish Date: Mar 31, 2020 04:37 AM
URL: CVE-2020-11113
Threat Assessment
Exploit Maturity:Not Defined
EPSS:6.278%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11113
Release Date: Mar 31, 2020 04:37 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4;2.10.0
🔴CVE-2020-36179
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
Publish Date: Jan 06, 2021 10:30 PM
URL: CVE-2020-36179
Threat Assessment
Exploit Maturity:Not Defined
EPSS:20.929%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3004
Release Date: Jan 06, 2021 10:30 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36180
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
Publish Date: Jan 06, 2021 10:30 PM
URL: CVE-2020-36180
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.041%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3004
Release Date: Jan 06, 2021 10:30 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36181
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
Publish Date: Jan 06, 2021 10:29 PM
URL: CVE-2020-36181
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.018%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3004
Release Date: Jan 06, 2021 10:29 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36182
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
Publish Date: Jan 06, 2021 10:30 PM
URL: CVE-2020-36182
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.018%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3004
Release Date: Jan 06, 2021 10:30 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36184
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
Publish Date: Jan 06, 2021 10:30 PM
URL: CVE-2020-36184
Threat Assessment
Exploit Maturity:Not Defined
EPSS:10.379%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2998
Release Date: Jan 06, 2021 10:30 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-10650
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.
Publish Date: Dec 26, 2022 12:00 AM
URL: CVE-2020-10650
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.328%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: GHSA-rpr3-cw39-3pxh
Release Date: Dec 26, 2022 12:00 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4
🔴CVE-2020-11619
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
Publish Date: Apr 07, 2020 10:14 PM
URL: CVE-2020-11619
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.607%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11619
Release Date: Apr 07, 2020 10:14 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4
🔴CVE-2020-11620
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
Publish Date: Apr 07, 2020 10:14 PM
URL: CVE-2020-11620
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.64%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11620
Release Date: Apr 07, 2020 10:14 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4
🔴CVE-2020-14060
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).
Publish Date: Jun 14, 2020 08:46 PM
URL: CVE-2020-14060
Threat Assessment
Exploit Maturity:Not Defined
EPSS:8.607%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14060
Release Date: Jun 14, 2020 08:46 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.10.0
🔴CVE-2020-14061
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms).
Publish Date: Jun 14, 2020 07:42 PM
URL: CVE-2020-14061
Threat Assessment
Exploit Maturity:Not Defined
EPSS:4.458%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14061
Release Date: Jun 14, 2020 07:42 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.10.0
🔴CVE-2020-14062
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).
Publish Date: Jun 14, 2020 07:42 PM
URL: CVE-2020-14062
Threat Assessment
Exploit Maturity:Not Defined
EPSS:8.072%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14062
Release Date: Jun 14, 2020 07:42 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.10.0
🔴CVE-2020-14195
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
Publish Date: Jun 16, 2020 03:07 PM
URL: CVE-2020-14195
Threat Assessment
Exploit Maturity:Not Defined
EPSS:4.549%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14195
Release Date: Jun 16, 2020 03:07 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.5
🔴CVE-2020-24616
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
Publish Date: Aug 25, 2020 05:04 PM
URL: CVE-2020-24616
Threat Assessment
Exploit Maturity:Not Defined
EPSS:9.422%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24616
Release Date: Aug 25, 2020 05:04 PM
Fix Resolution : 2.9.10.6
🔴CVE-2020-24750
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
Publish Date: Sep 17, 2020 06:39 PM
URL: CVE-2020-24750
Threat Assessment
Exploit Maturity:Not Defined
EPSS:7.327%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24616
Release Date: Sep 17, 2020 06:39 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.6
🔴CVE-2020-35490
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
Publish Date: Dec 17, 2020 06:43 PM
URL: CVE-2020-35490
Threat Assessment
Exploit Maturity:Not Defined
EPSS:7.694%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2986
Release Date: Dec 17, 2020 06:43 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-35491
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
Publish Date: Dec 17, 2020 06:43 PM
URL: CVE-2020-35491
Threat Assessment
Exploit Maturity:Not Defined
EPSS:9.477%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2986
Release Date: Dec 17, 2020 06:43 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-35728
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).
Publish Date: Dec 27, 2020 04:32 AM
URL: CVE-2020-35728
Threat Assessment
Exploit Maturity:Not Defined
EPSS:12.504%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35728
Release Date: Dec 27, 2020 04:32 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36183
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.
Publish Date: Jan 06, 2021 10:30 PM
URL: CVE-2020-36183
Threat Assessment
Exploit Maturity:Not Defined
EPSS:4.89%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3003
Release Date: Jan 06, 2021 10:30 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36185
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.
Publish Date: Jan 06, 2021 10:29 PM
URL: CVE-2020-36185
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.218%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2998
Release Date: Jan 06, 2021 10:29 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36186
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.
Publish Date: Jan 06, 2021 10:29 PM
URL: CVE-2020-36186
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.218%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2997
Release Date: Jan 06, 2021 10:29 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36187
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.
Publish Date: Jan 06, 2021 10:29 PM
URL: CVE-2020-36187
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.195%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2997
Release Date: Jan 06, 2021 10:29 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36188
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.
Publish Date: Jan 06, 2021 10:29 PM
URL: CVE-2020-36188
Threat Assessment
Exploit Maturity:Not Defined
EPSS:10.911%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2996
Release Date: Jan 06, 2021 10:29 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36189
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.
Publish Date: Jan 06, 2021 10:29 PM
URL: CVE-2020-36189
Threat Assessment
Exploit Maturity:Not Defined
EPSS:4.912%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2996
Release Date: Jan 06, 2021 10:29 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2021-20190
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Publish Date: Jan 19, 2021 04:27 PM
URL: CVE-2021-20190
Threat Assessment
Exploit Maturity:Not Defined
EPSS:7.483%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2854
Release Date: Jan 19, 2021 04:27 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind-2.9.10.7
🔴CVE-2020-25649
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
Publish Date: Dec 03, 2020 04:16 PM
URL: CVE-2020-25649
Threat Assessment
Exploit Maturity:Not Defined
EPSS:17.611%
Score: 7.5
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2589
Release Date: Dec 03, 2020 04:16 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.6.7.4,2.9.10.7,2.10.5.1,2.11.0.rc1
🔴CVE-2022-42003
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.
Publish Date: Oct 02, 2022 12:00 AM
URL: CVE-2022-42003
Threat Assessment
Exploit Maturity:Not Defined
EPSS:2.766%
Score: 7.5
Suggested Fix
Type: Upgrade version
Origin: GHSA-jjjh-jjxp-wpff
Release Date: Oct 02, 2022 12:00 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.12.7.1,2.13.4.2
🔴CVE-2022-42004
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.
Publish Date: Oct 02, 2022 12:00 AM
URL: CVE-2022-42004
Threat Assessment
Exploit Maturity:Not Defined
EPSS:2.766%
Score: 7.5
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3582
Release Date: Oct 02, 2022 12:00 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.13.4
🟠CVE-2026-54514
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
Publish Date: Jun 23, 2026 08:51 PM
URL: CVE-2026-54514
Threat Assessment
Exploit Maturity:Not Defined
EPSS:< 1%
Score: 5.3
Suggested Fix
Type: Upgrade version
Origin: FasterXML/jackson-databind@1f5a103
Release Date: Jun 23, 2026 08:51 PM
Fix Resolution : https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.8
🟠CVE-2026-54515
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
- ❌ jackson-databind-2.9.10.jar (Vulnerable Library)
Vulnerability Details
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.
Publish Date: Jun 23, 2026 08:50 PM
URL: CVE-2026-54515
Threat Assessment
Exploit Maturity:Not Defined
EPSS:< 1%
Score: 5.3
Suggested Fix
Type: Upgrade version
Origin: FasterXML/jackson-databind@0e1b0b2
Release Date: Jun 23, 2026 08:50 PM
Fix Resolution : https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4,com.fasterxml.jackson.core:jackson-databind:2.21.5,com.fasterxml.jackson.core:jackson-databind:2.22.1,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.9,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.21.5,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.22.1
📂 Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Findings
Details
🟣CVE-2019-16942
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.
Publish Date: Oct 01, 2019 04:04 PM
URL: CVE-2019-16942
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.728%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://osv.dev/vulnerability/GHSA-mx7p-6679-8g3q
Release Date: Oct 01, 2019 04:04 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.8.11.5,2.9.10.1
🟣CVE-2019-16943
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.
Publish Date: Oct 01, 2019 04:06 PM
URL: CVE-2019-16943
Threat Assessment
Exploit Maturity:Not Defined
EPSS:4.901%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://osv.dev/vulnerability/GHSA-fmmc-742q-jg75
Release Date: Oct 01, 2019 04:06 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.8.11.5,2.9.10.1
🟣CVE-2019-20330
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
Publish Date: Jan 03, 2020 03:35 AM
URL: CVE-2019-20330
Threat Assessment
Exploit Maturity:Not Defined
EPSS:8.64%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2526
Release Date: Jan 03, 2020 03:35 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.5,2.9.10.2
🟣CVE-2020-8840
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
Publish Date: Feb 10, 2020 07:41 PM
URL: CVE-2020-8840
Threat Assessment
Exploit Maturity:Not Defined
EPSS:26.587%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2620
Release Date: Feb 10, 2020 07:41 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.3
🟣CVE-2020-9546
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
Publish Date: Mar 02, 2020 03:59 AM
URL: CVE-2020-9546
Threat Assessment
Exploit Maturity:Not Defined
EPSS:4.613%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9546
Release Date: Mar 02, 2020 03:59 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.10.3
🟣CVE-2020-9547
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
Publish Date: Mar 02, 2020 03:59 AM
URL: CVE-2020-9547
Threat Assessment
Exploit Maturity:Not Defined
EPSS:17.757%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://osv.dev/vulnerability/GHSA-q93h-jc49-78gg
Release Date: Mar 02, 2020 03:59 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.6,2.9.10.4
🟣CVE-2020-9548
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
Publish Date: Mar 02, 2020 03:58 AM
URL: CVE-2020-9548
Threat Assessment
Exploit Maturity:Not Defined
EPSS:18.345%
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9548
Release Date: Mar 02, 2020 03:58 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.6,2.9.10.4
🔴CVE-2020-10672
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
Publish Date: Mar 18, 2020 09:17 PM
URL: CVE-2020-10672
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.059%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2020-10672
Release Date: Mar 18, 2020 09:17 PM
Fix Resolution : jackson-databind-2.9.10.4
🔴CVE-2020-10673
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
Publish Date: Mar 18, 2020 09:17 PM
URL: CVE-2020-10673
Threat Assessment
Exploit Maturity:Not Defined
EPSS:8.028%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2660
Release Date: Mar 18, 2020 09:17 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4
🔴CVE-2020-10968
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
Publish Date: Mar 26, 2020 12:43 PM
URL: CVE-2020-10968
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.538%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2020-10968
Release Date: Mar 26, 2020 12:43 PM
Fix Resolution : jackson-databind-2.9.10.4
🔴CVE-2020-10969
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
Publish Date: Mar 26, 2020 12:43 PM
URL: CVE-2020-10969
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.473%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10969
Release Date: Mar 26, 2020 12:43 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.8.11.6;com.fasterxml.jackson.core:jackson-databind:2.7.9.7
🔴CVE-2020-11111
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
Publish Date: Mar 31, 2020 04:37 AM
URL: CVE-2020-11111
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.489%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11113
Release Date: Mar 31, 2020 04:37 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4,2.10.0
🔴CVE-2020-11112
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
Publish Date: Mar 31, 2020 04:37 AM
URL: CVE-2020-11112
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.583%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11112
Release Date: Mar 31, 2020 04:37 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4,2.10.0
🔴CVE-2020-11113
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
Publish Date: Mar 31, 2020 04:37 AM
URL: CVE-2020-11113
Threat Assessment
Exploit Maturity:Not Defined
EPSS:6.278%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11113
Release Date: Mar 31, 2020 04:37 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4;2.10.0
🔴CVE-2020-36179
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
Publish Date: Jan 06, 2021 10:30 PM
URL: CVE-2020-36179
Threat Assessment
Exploit Maturity:Not Defined
EPSS:20.929%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3004
Release Date: Jan 06, 2021 10:30 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36180
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
Publish Date: Jan 06, 2021 10:30 PM
URL: CVE-2020-36180
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.041%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3004
Release Date: Jan 06, 2021 10:30 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36181
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
Publish Date: Jan 06, 2021 10:29 PM
URL: CVE-2020-36181
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.018%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3004
Release Date: Jan 06, 2021 10:29 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36182
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
Publish Date: Jan 06, 2021 10:30 PM
URL: CVE-2020-36182
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.018%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3004
Release Date: Jan 06, 2021 10:30 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36184
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
Publish Date: Jan 06, 2021 10:30 PM
URL: CVE-2020-36184
Threat Assessment
Exploit Maturity:Not Defined
EPSS:10.379%
Score: 8.8
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2998
Release Date: Jan 06, 2021 10:30 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-10650
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.
Publish Date: Dec 26, 2022 12:00 AM
URL: CVE-2020-10650
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.328%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: GHSA-rpr3-cw39-3pxh
Release Date: Dec 26, 2022 12:00 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4
🔴CVE-2020-11619
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
Publish Date: Apr 07, 2020 10:14 PM
URL: CVE-2020-11619
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.607%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11619
Release Date: Apr 07, 2020 10:14 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4
🔴CVE-2020-11620
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
Publish Date: Apr 07, 2020 10:14 PM
URL: CVE-2020-11620
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.64%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11620
Release Date: Apr 07, 2020 10:14 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.4
🔴CVE-2020-14060
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).
Publish Date: Jun 14, 2020 08:46 PM
URL: CVE-2020-14060
Threat Assessment
Exploit Maturity:Not Defined
EPSS:8.607%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14060
Release Date: Jun 14, 2020 08:46 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.10.0
🔴CVE-2020-14061
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms).
Publish Date: Jun 14, 2020 07:42 PM
URL: CVE-2020-14061
Threat Assessment
Exploit Maturity:Not Defined
EPSS:4.458%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14061
Release Date: Jun 14, 2020 07:42 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.10.0
🔴CVE-2020-14062
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).
Publish Date: Jun 14, 2020 07:42 PM
URL: CVE-2020-14062
Threat Assessment
Exploit Maturity:Not Defined
EPSS:8.072%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14062
Release Date: Jun 14, 2020 07:42 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.10.0
🔴CVE-2020-14195
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
Publish Date: Jun 16, 2020 03:07 PM
URL: CVE-2020-14195
Threat Assessment
Exploit Maturity:Not Defined
EPSS:4.549%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14195
Release Date: Jun 16, 2020 03:07 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.5
🔴CVE-2020-24616
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
Publish Date: Aug 25, 2020 05:04 PM
URL: CVE-2020-24616
Threat Assessment
Exploit Maturity:Not Defined
EPSS:9.422%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24616
Release Date: Aug 25, 2020 05:04 PM
Fix Resolution : 2.9.10.6
🔴CVE-2020-24750
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
Publish Date: Sep 17, 2020 06:39 PM
URL: CVE-2020-24750
Threat Assessment
Exploit Maturity:Not Defined
EPSS:7.327%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24616
Release Date: Sep 17, 2020 06:39 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.6
🔴CVE-2020-35490
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
Publish Date: Dec 17, 2020 06:43 PM
URL: CVE-2020-35490
Threat Assessment
Exploit Maturity:Not Defined
EPSS:7.694%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2986
Release Date: Dec 17, 2020 06:43 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-35491
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
Publish Date: Dec 17, 2020 06:43 PM
URL: CVE-2020-35491
Threat Assessment
Exploit Maturity:Not Defined
EPSS:9.477%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2986
Release Date: Dec 17, 2020 06:43 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-35728
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).
Publish Date: Dec 27, 2020 04:32 AM
URL: CVE-2020-35728
Threat Assessment
Exploit Maturity:Not Defined
EPSS:12.504%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35728
Release Date: Dec 27, 2020 04:32 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36183
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.
Publish Date: Jan 06, 2021 10:30 PM
URL: CVE-2020-36183
Threat Assessment
Exploit Maturity:Not Defined
EPSS:4.89%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3003
Release Date: Jan 06, 2021 10:30 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36185
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.
Publish Date: Jan 06, 2021 10:29 PM
URL: CVE-2020-36185
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.218%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2998
Release Date: Jan 06, 2021 10:29 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36186
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.
Publish Date: Jan 06, 2021 10:29 PM
URL: CVE-2020-36186
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.218%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2997
Release Date: Jan 06, 2021 10:29 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36187
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.
Publish Date: Jan 06, 2021 10:29 PM
URL: CVE-2020-36187
Threat Assessment
Exploit Maturity:Not Defined
EPSS:5.195%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2997
Release Date: Jan 06, 2021 10:29 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36188
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.
Publish Date: Jan 06, 2021 10:29 PM
URL: CVE-2020-36188
Threat Assessment
Exploit Maturity:Not Defined
EPSS:10.911%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2996
Release Date: Jan 06, 2021 10:29 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2020-36189
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.
Publish Date: Jan 06, 2021 10:29 PM
URL: CVE-2020-36189
Threat Assessment
Exploit Maturity:Not Defined
EPSS:4.912%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2996
Release Date: Jan 06, 2021 10:29 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.9.10.8
🔴CVE-2021-20190
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Publish Date: Jan 19, 2021 04:27 PM
URL: CVE-2021-20190
Threat Assessment
Exploit Maturity:Not Defined
EPSS:7.483%
Score: 8.1
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2854
Release Date: Jan 19, 2021 04:27 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind-2.9.10.7
🔴CVE-2020-25649
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
Publish Date: Dec 03, 2020 04:16 PM
URL: CVE-2020-25649
Threat Assessment
Exploit Maturity:Not Defined
EPSS:17.611%
Score: 7.5
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/2589
Release Date: Dec 03, 2020 04:16 PM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.6.7.4,2.9.10.7,2.10.5.1,2.11.0.rc1
🔴CVE-2022-42003
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.
Publish Date: Oct 02, 2022 12:00 AM
URL: CVE-2022-42003
Threat Assessment
Exploit Maturity:Not Defined
EPSS:2.766%
Score: 7.5
Suggested Fix
Type: Upgrade version
Origin: GHSA-jjjh-jjxp-wpff
Release Date: Oct 02, 2022 12:00 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.12.7.1,2.13.4.2
🔴CVE-2022-42004
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.
Publish Date: Oct 02, 2022 12:00 AM
URL: CVE-2022-42004
Threat Assessment
Exploit Maturity:Not Defined
EPSS:2.766%
Score: 7.5
Suggested Fix
Type: Upgrade version
Origin: https://redirect.github.com/FasterXML/jackson-databind/issues/3582
Release Date: Oct 02, 2022 12:00 AM
Fix Resolution : com.fasterxml.jackson.core:jackson-databind:2.13.4
🟠CVE-2026-54514
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
Publish Date: Jun 23, 2026 08:51 PM
URL: CVE-2026-54514
Threat Assessment
Exploit Maturity:Not Defined
EPSS:< 1%
Score: 5.3
Suggested Fix
Type: Upgrade version
Origin: FasterXML/jackson-databind@1f5a103
Release Date: Jun 23, 2026 08:51 PM
Fix Resolution : https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.8
🟠CVE-2026-54515
Vulnerable Library - jackson-databind-2.9.10.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: http://fasterxml.com/
Path to dependency file: /pom.xml
Dependency Hierarchy:
Vulnerability Details
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.
Publish Date: Jun 23, 2026 08:50 PM
URL: CVE-2026-54515
Threat Assessment
Exploit Maturity:Not Defined
EPSS:< 1%
Score: 5.3
Suggested Fix
Type: Upgrade version
Origin: FasterXML/jackson-databind@0e1b0b2
Release Date: Jun 23, 2026 08:50 PM
Fix Resolution : https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4,com.fasterxml.jackson.core:jackson-databind:2.21.5,com.fasterxml.jackson.core:jackson-databind:2.22.1,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.9,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.21.5,https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.22.1