CVE-2020-11619

Aliases:GHSA-27xj-rqx5-2255DEBIAN-CVE-2020-11619CGA-29j7-qpj7-84w6CGA-2fvj-3cj2-95p3CGA-4mrj-q497-4mxgCGA-5frc-qj3j-p2g5CGA-6q2h-6887-w9ppCGA-8ggr-rrwr-c7r7CGA-cg77-mf56-xw3hCGA-fvm2-4h2x-5j62CGA-j7x4-grrf-623xCGA-m8cf-ggx6-hh6jCGA-ppfv-mrr5-cffxCGA-r92m-h6r7-v2jqCGA-rpcw-3xvm-h358CGA-w2xj-273g-p3wxCGA-27hw-rxpc-8g76CGA-4j4x-r79m-8x87CGA-8h2w-jv6h-2c95CGA-c8vq-jgjp-vhxwCGA-gcfh-8753-675hCGA-gx7m-3mr4-gx58CGA-j2vj-2gg5-9954CGA-j43g-92ph-h5qvCGA-wpm2-pqfc-4c8rCGA-3qm5-28h3-4m2jCGA-49h2-j6xc-4hwqCGA-4cmj-9cq9-pwf9CGA-4jwx-vjqc-65xrCGA-5g97-8hcq-g6xqCGA-5hj7-q72x-mqqrCGA-6779-j64m-x3fgCGA-6gcc-6xmf-m9rhCGA-97w8-w963-j245CGA-9xcc-mvh7-vf42CGA-fhvp-r7pp-mc55CGA-fxjc-5fg3-wvh5CGA-hhcx-7pm5-8pqmCGA-hwh7-4w9j-ffchCGA-pqm5-3g4w-2xw6CGA-px4c-j4mr-jhjfCGA-q9mm-gg2h-vqcpCGA-rjmj-hhcm-97vfCGA-whgh-pqxm-gmggCGA-wqwm-6vjg-r4xjCGA-2875-f9xc-54r4CGA-5jgx-pwj9-43wfCGA-64gw-55fj-ffjqCGA-6ph5-hxp9-54qhCGA-9gxw-c64r-w867CGA-9vcf-8ccj-8jc9CGA-c342-jw74-j8jcCGA-gjgc-8v8r-q7m3CGA-j75v-j354-6fc8CGA-jhqr-jrvh-ph6hCGA-jjr2-xjpc-x4mrCGA-qpmx-f9hh-7v8mCGA-v2h7-3hjp-5g7g
Advisory lineage Upstream: 0 Downstream: 9
Analyzed
Published: 07 Apr 2020, 22:14
Last modified:04 Aug 2024, 11:35

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.1 HIGH
v3.1 (nvd)
EPSS Score
3.7% LOW
4% probability +1.97%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

07 Apr 2020, 22:14
Published
Vulnerability first disclosed
04 Aug 2024, 11:35
Last Modified
Vulnerability information updated

Description

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 3.70% Percentile: 89%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • chainguardeco-java-gradle-4.10

    all

  • chainguardeco-java-gradle-4.10.1

    all

  • chainguardeco-java-gradle-4.10.2

    all

  • chainguardeco-java-gradle-4.10.3

    all

  • chainguardeco-java-gradle-4.9

    all

  • chainguardeco-java-gradle-5.0

    all

  • chainguardeco-java-gradle-5.1

    all

  • chainguardeco-java-gradle-5.1.1

    all

  • chainguardeco-java-gradle-5.2

    all

  • chainguardeco-java-gradle-5.2.1

    all

  • chainguardeco-java-gradle-5.3

    all

  • chainguardeco-java-gradle-5.3.1

    all

  • chainguardeco-java-gradle-5.4

    all

  • chainguardeco-java-gradle-5.4.1

    all

  • chainguardeco-java-gradle-5.5

    all

  • chainguardeco-java-gradle-5.5.1

    all

  • chainguardeco-java-gradle-5.6

    all

  • chainguardeco-java-gradle-5.6.1

    all

  • chainguardeco-java-gradle-5.6.2

    all

  • chainguardeco-java-gradle-5.6.3

    all

  • chainguardeco-java-gradle-5.6.4

    all

  • chainguardeco-java-gradle-6.0

    all

  • chainguardeco-java-gradle-6.0.1

    all

  • chainguardeco-java-gradle-6.1

    all

  • chainguardeco-java-gradle-6.1.1

    all

  • chainguardeco-java-gradle-6.2

    all

  • chainguardeco-java-gradle-6.2.1

    all

  • chainguardeco-java-gradle-6.2.2

    all

  • debianjackson-databind

    < 2.11.1-1 | < 2.11.1-1 | < 2.11.1-1 | < 2.11.1-1

  • debiandebian_linux

    8.0

  • fasterxmljackson-databind

    ≥ 2.9.0, < 2.9.10.4 | ≥ 2.0.0, < 2.9.10.4

  • com.fasterxml.jackson.corejackson-databind

    ≥ 2.9.0, < 2.9.10.4

  • netappactive_iq_unified_manager

    ≥ 7.3 | ≥ 9.5

  • netappsteelstore_cloud_integrated_storage

    na

  • oracleagile_plm

    9.3.6

  • oracleagile_product_lifecycle_management

    9.3.6

  • oraclebanking_platform

    ≥ 2.4.0, ≤ 2.9.0

  • oraclecommunications_calendar_server

    8.0.0.4.0

  • oraclecommunications_contacts_server

    8.0.0.4.0 | 8.0.0.5.0

  • oraclecommunications_diameter_signaling_router

    ≥ 8.0.0, ≤ 8.2.2

  • oraclecommunications_evolved_communications_application_server

    7.1

  • oraclecommunications_instant_messaging_server

    10.0.1.4.0

  • oraclecommunications_network_charging_and_control

    ≥ 12.0.0, ≤ 12.0.3 | 6.0.1

  • oracleenterprise_manager_base_platform

    13.3.0.0 | 13.4.0.0

  • oracleglobal_lifecycle_management_opatch

    < 12.2.0.1.20

  • oraclejd_edwards_enterpriseone_orchestrator

    < 9.2.4.2

  • oraclejd_edwards_enterpriseone_tools

    < 9.2.4.2

  • oracleprimavera_unifier

    ≥ 17.7, ≤ 17.12 | 16.1 | 16.2 | 18.8 | 19.12

  • oracleretail_merchandising_system

    15.0

  • oracleretail_sales_audit

    14.1

Showing first 50 affected entries in server-rendered view.

References (14)