CVE-2020-35490
- EPSS 7.69%
- Veröffentlicht 17.12.2020 19:15:14
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
CVE-2020-35491
- EPSS 9.48%
- Veröffentlicht 17.12.2020 19:15:14
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
CVE-2020-17521
- EPSS 1.05%
- Veröffentlicht 07.12.2020 20:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operatin...
CVE-2020-25649
- EPSS 17.61%
- Veröffentlicht 03.12.2020 17:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
CVE-2020-27193
- EPSS 2.04%
- Veröffentlicht 12.11.2020 21:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
CVE-2020-24750
- EPSS 7.33%
- Veröffentlicht 17.09.2020 19:15:13
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
CVE-2020-24616
- EPSS 9.42%
- Veröffentlicht 25.08.2020 18:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
CVE-2020-13934
- EPSS 64.12%
- Veröffentlicht 14.07.2020 15:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException co...
CVE-2020-13935
- EPSS 86.61%
- Veröffentlicht 14.07.2020 15:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with inv...
CVE-2020-14195
- EPSS 4.55%
- Veröffentlicht 16.06.2020 16:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).