CVE-2020-5398
- EPSS 90.57%
- Published 17.01.2020 00:15:12
- Last modified 21.11.2024 05:34:04
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response...
CVE-2019-20330
- EPSS 2%
- Published 03.01.2020 04:15:12
- Last modified 21.11.2024 04:38:16
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CVE-2019-17531
- EPSS 1.19%
- Published 12.10.2019 21:15:08
- Last modified 21.11.2024 04:32:27
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-ext...
CVE-2019-16942
- EPSS 0.44%
- Published 01.10.2019 17:15:10
- Last modified 21.11.2024 04:31:23
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1....
CVE-2019-16943
- EPSS 1.84%
- Published 01.10.2019 17:15:10
- Last modified 21.11.2024 04:31:23
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) ja...
CVE-2019-14439
- EPSS 9.41%
- Published 30.07.2019 11:15:11
- Last modified 21.11.2024 04:26:44
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logbac...
CVE-2019-14379
- EPSS 1.46%
- Published 29.07.2019 12:15:16
- Last modified 21.11.2024 04:26:37
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
CVE-2018-14718
- EPSS 14.75%
- Published 02.01.2019 18:29:00
- Last modified 21.11.2024 03:49:39
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.