CVE-2021-20190

Published Jan 19, 2021

Last updated 2 months ago

Overview

Description
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Source
secalert@redhat.com
NVD status
Analyzed
Products
jackson-databind, active_iq_unified_manager, oncommand_api_services, oncommand_insight, service_level_manager, nifi, debian_linux, commerce_experience_manager, commerce_guided_search

Risk scores

CVSS 3.1

Type
Primary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

CVSS 2.0

Type
Primary
Base score
8.3
Impact score
8.5
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:P/I:P/A:C

Weaknesses

secalert@redhat.com
CWE-502
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-502

Social media

Hype score
Not currently trending

Configurations