Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian Stretch: DLA-2638-1 Moderate: Jackson-Databind Data Issues

debian lts
Calendar Grey April 24, 2021
Dist Debian Esm H88
Ubuntu Security Notice USN-5247-1 reveals critical issues in libc-bin necessitating urgent patches for safeguarding systems.
Multiple security vulnerabilities were found in Jackson Databind

Summary

CVE-2020-24616

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the
interaction between serialization gadgets and typing, related
to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).

CVE-2020-24750

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the
interaction between serialization gadgets and typing, related
to com.pastdev.httpcomponents.configuration.JndiConfiguration.

CVE-2020-25649

A flaw was found in FasterXML Jackson Databind, where it did not
have entity expansion secured properly. This flaw allows
vulnerability to XML external entity (XXE) attacks. The highest
threat from this vulnerability is data integrity.

CVE-2020-35490

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the
interaction between serialization gadgets and typing, related
to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.

CVE-2020-35491

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Package: jackson-databind
Version: 2.8.6-1+deb9u9
CVE ID: CVE-2020-24616 CVE-2020-24750 CVE-2020-35490

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here