CVE-2020-14195
Aliases:GHSA-mc6h-4qgp-37qhDEBIAN-CVE-2020-14195CGA-2853-xrqr-r9hqCGA-4c5c-866w-j2jgCGA-5j2v-ch4c-5g87CGA-5ppg-chq2-vg28CGA-64qv-j95j-ppprCGA-92xp-v56c-mwwhCGA-95fg-7hgc-2wr4CGA-9mq8-fgmr-89rrCGA-c2h6-542w-6w7xCGA-cvh9-3r97-h6q4CGA-cxjw-2mjh-vp3fCGA-fw5r-w2x4-rw8mCGA-hxqf-x3m5-98r8CGA-vw2c-xgv5-63wmCGA-3j89-q27m-994qCGA-c5r5-p7jh-mf72CGA-cxrf-vrjr-8g2hCGA-fm4r-v5p6-cfhwCGA-h43v-q2qq-c3jwCGA-rq8x-hm77-w56fCGA-264c-fqq3-75pjCGA-2fhv-8w2g-f57xCGA-3552-wwgf-pmqvCGA-376f-wc25-wx45CGA-6xvj-2hvj-4723CGA-9c39-7xmp-pwrmCGA-c262-26mp-qg5rCGA-ccv5-2rrx-rqwjCGA-f6gq-77p2-3frxCGA-f7mf-47p5-x7vrCGA-jhv2-7cj5-26mpCGA-mxfw-cp6g-j89fCGA-pgg2-6qw4-v75cCGA-pmhj-hvr7-3cmgCGA-r4gp-x6h4-3x45CGA-r4j4-chjc-9jfxCGA-r4xj-6m6v-4cxmCGA-rcgq-gcq3-rhphCGA-v7qp-5q9c-vj89CGA-x9qw-67v5-87xcCGA-3jvg-fwfg-qprrCGA-4495-cfqw-3g5fCGA-4www-2jh7-p477CGA-7vgr-g64m-hr49CGA-92gj-7xrw-v3h3CGA-96h3-62x5-6mrpCGA-96qx-7gmq-pqg6CGA-9xc2-wff5-jqr7CGA-p67w-74rg-87wpCGA-pmqg-qqjx-7565CGA-pqc7-6wxx-wpc8CGA-r4v8-fv7v-jhc7CGA-r9xw-q79x-g5gvCGA-rjxw-c5hq-3p2pCGA-vqph-6x62-4rmmCGA-w3q7-2x84-j4v6
Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 16 Jun 2020, 15:07
Last modified:04 Aug 2024, 12:39
Vulnerability Summary
Overall Risk (default)
medium
33/100 CVSS Score
8.1 HIGH
v3.1 (nvd)
EPSS Score
4.55% LOW
5% probability -4.96%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
16 Jun 2020, 15:07
Published
Vulnerability first disclosed
04 Aug 2024, 12:39
Last Modified
Vulnerability information updated
Description
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
CVSS Metrics
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- v2.0•MEDIUM•Score: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 4.55%• Percentile: 91%
Techniques & Countermeasures
- CWE-502•Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Affected Systems
- chainguard•eco-java-gradle-4.10
all
- chainguard•eco-java-gradle-4.10.1
all
- chainguard•eco-java-gradle-4.10.2
all
- chainguard•eco-java-gradle-4.10.3
all
- chainguard•eco-java-gradle-4.9
all
- chainguard•eco-java-gradle-5.0
all
- chainguard•eco-java-gradle-5.1
all
- chainguard•eco-java-gradle-5.1.1
all
- chainguard•eco-java-gradle-5.2
all
- chainguard•eco-java-gradle-5.2.1
all
- chainguard•eco-java-gradle-5.3
all
- chainguard•eco-java-gradle-5.3.1
all
- chainguard•eco-java-gradle-5.4
all
- chainguard•eco-java-gradle-5.4.1
all
- chainguard•eco-java-gradle-5.5
all
- chainguard•eco-java-gradle-5.5.1
all
- chainguard•eco-java-gradle-5.6
all
- chainguard•eco-java-gradle-5.6.1
all
- chainguard•eco-java-gradle-5.6.2
all
- chainguard•eco-java-gradle-5.6.3
all
- chainguard•eco-java-gradle-5.6.4
all
- chainguard•eco-java-gradle-6.0
all
- chainguard•eco-java-gradle-6.0.1
all
- chainguard•eco-java-gradle-6.1
all
- chainguard•eco-java-gradle-6.1.1
all
- chainguard•eco-java-gradle-6.2
all
- chainguard•eco-java-gradle-6.2.1
all
- chainguard•eco-java-gradle-6.2.2
all
- debian•jackson-databind
< 2.11.1-1 | < 2.11.1-1 | < 2.11.1-1 | < 2.11.1-1
- debian•debian_linux
8.0
- fasterxml•jackson-databind
≥ 2.9.0, < 2.9.10.5
- com.fasterxml.jackson.core•jackson-databind
≥ 2.9.0, < 2.9.10.5
- netapp•active_iq_unified_manager
≥ 7.3 | ≥ 9.5
- netapp•steelstore_cloud_integrated_storage
na
- oracle•agile_plm
9.3.6
- oracle•agile_product_lifecycle_management
9.3.6
- oracle•banking_digital_experience
18.1 | 18.2 | 18.3 | 19.1 | 19.2 | 20.1
- oracle•communications_calendar_server
8.0.0.4.0
- oracle•communications_contacts_server
8.0.0.5.0
- oracle•communications_diameter_signaling_router
≥ 8.0.0, ≤ 8.2.2
- oracle•communications_element_manager
≥ 8.2.0, ≤ 8.2.2
- oracle•communications_evolved_communications_application_server
7.1
- oracle•communications_instant_messaging_server
10.0.1.4.0
- oracle•communications_session_report_manager
≥ 8.2.0, ≤ 8.2.2
- oracle•communications_session_route_manager
≥ 8.2.0, ≤ 8.2.2
References (14)
- https://github.com/FasterXML/jackson-databind/issues/2765
- https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://security.netapp.com/advisory/ntap-20200702-0003/
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://nvd.nist.gov/vuln/detail/CVE-2020-14195
- https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88
- https://github.com/FasterXML/jackson-databind/commit/f6d9c664f6d481703138319f6a0f1fdbddb3a259
- https://github.com/FasterXML/jackson-databind
- https://security.netapp.com/advisory/ntap-20200702-0003
- https://security-tracker.debian.org/tracker/CVE-2020-14195