← לוח פגיעויות

CVE-2021-20190

גבוהה 8.1

תיאור (מקור, אנגלית)

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

מדדים

CVSS 3.1
8.1 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
7% (אחוזון 100) נכון ל-30/7/2026
CWE
CWE-502

מוצרים מושפעים

fasterxml: jackson-databind; netapp: active iq unified manager; netapp: oncommand api services; netapp: oncommand insight; netapp: service level manager; apache: nifi; debian: debian linux; oracle: commerce experience manager; oracle: commerce guided search

קישורים