CVE-2020-36182: High severity fasterxml jackson-databind vulnerability
A flaw was found in jackson-databind. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
FasterXML jackson-databind 2.x before 2.9.10.8 and 2.6.7.5 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-36182?
CVE-2020-36182 has a high severity and poses risks to data confidentiality, integrity, and system availability.
How do I fix CVE-2020-36182?
To mitigate CVE-2020-36182, update jackson-databind to version 2.6.7.5 or 2.9.10.8 or later.
Which versions of jackson-databind are affected by CVE-2020-36182?
CVE-2020-36182 affects jackson-databind versions before 2.6.7.5 and 2.9.10.8.
What types of applications are impacted by CVE-2020-36182?
Applications utilizing jackson-databind for JSON serialization and deserialization are impacted by CVE-2020-36182.
Are there known exploits for CVE-2020-36182?
While there are no public exploits reported for CVE-2020-36182, its potential to compromise data security makes it critical to apply the necessary updates.