FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jackson-databind | Jul 2, 2020 | Jun 16, 2020 |
| Freebsd | — | Upgrade puppetdb5 | Aug 11, 2020 | Aug 11, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 16, 2020 |
| Ubuntu | — | Upgrade libjackson2-databind-java (Ubuntu Pro) | Mar 22, 2023 | Jun 16, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub