CVE-2019-20330: Deserialization of Untrusted Data
(updated )
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
References
- github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.10.1...jackson-databind-2.9.10.2
- github.com/FasterXML/jackson-databind/issues/2526
- github.com/advisories/GHSA-gww7-p5w4-wrfv
- lists.debian.org/debian-lts-announce/2020/02/msg00020.html
- nvd.nist.gov/vuln/detail/CVE-2019-20330
- security.netapp.com/advisory/ntap-20200127-0004/
- www.oracle.com/security-alerts/cpuapr2020.html
- www.oracle.com/security-alerts/cpujul2020.html
- www.oracle.com/security-alerts/cpuoct2020.html
Detect and mitigate CVE-2019-20330 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →