CVE-2020-35490: High severity fasterxml jackson-databind vulnerability
A flaw was found in jackson-databind. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-35490?
CVE-2020-35490 is a vulnerability in the FasterXML jackson-databind library that allows a remote attacker to execute arbitrary code on the system through unsafe deserialization.
How does CVE-2020-35490 impact the system?
CVE-2020-35490 allows an attacker to execute arbitrary code on the affected system.
What is the severity level of CVE-2020-35490?
CVE-2020-35490 has a severity level of 8.1 (high).
Which software versions are affected by CVE-2020-35490?
CVE-2020-35490 affects FasterXML jackson-databind versions up to and excluding 2.9.10.8.
How can I fix CVE-2020-35490?
To fix CVE-2020-35490, you need to upgrade FasterXML jackson-databind to version 2.9.10.8 or later.