Lucene search

K
osvGoogleOSV:CVE-2020-36182
HistoryJan 07, 2021 - 12:15 a.m.

CVE-2020-36182

2021-01-0700:15:14
Google
osv.dev
13
fasterxml jackson-databind
security vulnerability
serialization gadgets
typing
apache tomcat dbcp2
driveradaptercpds

AI Score

7.1

Confidence

Low

EPSS

0.003

Percentile

66.0%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.