Aller au contenu

Fiche vulnérabilité

CVE-2021-20190 : faille élevée fasterxml jackson-databind (CVSS 8.1)

Description

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

En bref

Sévérité
Élevée (CVSS 8.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
19 janv. 2021
Dernière mise à jour
24 juil. 2026

Produits concernés

  • fasterxml jackson-databind
  • netapp active iq unified manager
  • netapp oncommand api services
  • netapp oncommand insight
  • netapp service level manager
  • apache nifi
  • debian debian linux
  • oracle commerce experience manager
  • oracle commerce guided search

Références

Rechercher une autre vulnérabilité dans la base CVE