CVE-2020-14060: High severity fasterxml jackson-databind vulnerability
A flaw was found in jackson-databind 2.x in versions prior to 2.9.10.5. The interaction between serialization gadgets and typing is mishandled. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
A Vulnerability was found in FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool
References: https://github.com/FasterXML/jackson-databind/issues/2688 https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
— Red Hat
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).
Affected Software
Remediation
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-14060?
CVE-2020-14060 is a vulnerability in jackson-databind 2.x before 2.9.10.5 that mishandles the interaction between serialization gadgets and typing.
What is the severity of CVE-2020-14060?
The severity of CVE-2020-14060 is high, with a CVSS score of 8.1.
How does CVE-2020-14060 impact data confidentiality and integrity?
CVE-2020-14060 can lead to data confidentiality and integrity issues.
How can I fix CVE-2020-14060?
To fix CVE-2020-14060, update jackson-databind to version 2.9.10.5 or higher.
Where can I find more information about CVE-2020-14060?
You can find more information about CVE-2020-14060 on the following references: [link1](https://github.com/FasterXML/jackson-databind/issues/2688), [link2](https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1848968)