← Back

CVE-2020-11620

nvd nist
Published: Apr 7, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).

Affected (31)

Show all products
1 product
Jackson Databind
1 product
Debian Linux
2 products
Active Iq Unified Manager
14 products
Banking Platform
Communications Contacts Server
Enterprise Manager Base Platform
Jd Edwards Enterpriseone Tools
Primavera Unifier
Retail Merchandising System
Retail Sales Audit
Retail Xstore Point Of Service
Weblogic Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.9.0 to 2.9.10.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration C
4 vulnerable
Configuration D
25 vulnerable

References (16)

Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.