Lucene search

K
redhatcveRedhat.comRH:CVE-2020-10672
HistoryMay 14, 2022 - 11:38 a.m.

CVE-2020-10672

2022-05-1411:38:03
redhat.com
access.redhat.com
56
flaw
jackson-databind
serialization
typing
data confidentiality
data integrity
system availability

EPSS

0.008

Percentile

81.5%

A flaw was found in jackson-databind 2.x in versions prior to 2.9.10.4. FasterXML jackson-databind 2.x mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.