Fiche vulnérabilité
CVE-2021-20190 : faille élevée fasterxml jackson-databind (CVSS 8.1)
Description
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
En bref
- Sévérité
- Élevée (CVSS 8.1)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 19 janv. 2021
- Dernière mise à jour
- 24 juil. 2026
Produits concernés
- fasterxml jackson-databind
- netapp active iq unified manager
- netapp oncommand api services
- netapp oncommand insight
- netapp service level manager
- apache nifi
- debian debian linux
- oracle commerce experience manager
- oracle commerce guided search