FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-jackson-databind | Jul 2, 2020 | Jun 16, 2020 | |
| Freebsd | freebsd-upgrade-package-puppetdb5 | Aug 11, 2020 | Aug 11, 2020 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Jun 16, 2020 |
| Ubuntu | ubuntu-pro-upgrade-libjackson2-databind-java | Mar 22, 2023 | Jun 16, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub