ZeroHour

CVE-2020-24750

CVSS 3.1
8.1 high
EPSS
7%p94
Published
()
Modified
Description

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.

Vendors
fasterxmloracledebian
Products
jackson-databind, agile product lifecycle management, application testing suite, autovue for agile product lifecycle management, banking corporate lending process management, banking credit facilities process management, banking liquidity management, banking supply chain finance, blockchain platform, communications calendar server, communications contacts server, communications diameter signaling router
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.