CVE-2020-11620: High severity fasterxml jackson-databind vulnerability
A flaw was found in jackson-databind 2.x. The interaction between serialization gadgets and typing is mishandled. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-11620?
CVE-2020-11620 is a vulnerability found in jackson-databind 2.x that mishandles the interaction between serialization gadgets and typing.
What is the severity of CVE-2020-11620?
The severity of CVE-2020-11620 is high, with a severity value of 8.1.
What is affected by CVE-2020-11620?
Jackson-databind versions before 2.9.10.4 are affected by CVE-2020-11620.
How does CVE-2020-11620 impact system security?
CVE-2020-11620 poses a threat to data confidentiality and integrity, as well as system availability.
How can I fix CVE-2020-11620?
To fix CVE-2020-11620, update your jackson-databind version to 2.9.10.4 or higher.