FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jackson-databind | Jul 2, 2020 | Jun 14, 2020 |
| Freebsd | — | Upgrade puppetdb5 | Aug 11, 2020 | Aug 11, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 14, 2020 |
| Ubuntu | — | Upgrade libjackson2-databind-java (Ubuntu Pro) | Mar 22, 2023 | Jun 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub