ZeroHour

CVE-2021-20190

CVSS 3.1
8.1 high
EPSS
7%p94
Published
()
Modified
Description

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Vendors
fasterxmlnetappapachedebianoracle
Products
jackson-databind, active iq unified manager, oncommand api services, oncommand insight, service level manager, nifi, debian linux, commerce experience manager, commerce guided search
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.