Fasterxml

Jackson-databind

87 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.77%
  • Veröffentlicht 02.10.2022 05:15:09
  • Zuletzt bearbeitet 07.10.2026 17:16:43

In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enab...

Exploit
  • EPSS 2.77%
  • Veröffentlicht 02.10.2022 05:15:09
  • Zuletzt bearbeitet 07.10.2026 17:16:43

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choice...

Exploit
  • EPSS 4.86%
  • Veröffentlicht 11.03.2022 07:15:07
  • Zuletzt bearbeitet 27.08.2025 21:15:36

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

  • EPSS 7.48%
  • Veröffentlicht 19.01.2021 17:15:13
  • Zuletzt bearbeitet 24.07.2026 14:27:51

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Exploit
  • EPSS 4.89%
  • Veröffentlicht 07.01.2021 00:15:15
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.

Exploit
  • EPSS 5.02%
  • Veröffentlicht 07.01.2021 00:15:14
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.

Exploit
  • EPSS 5.04%
  • Veröffentlicht 07.01.2021 00:15:14
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.

Exploit
  • EPSS 20.93%
  • Veröffentlicht 07.01.2021 00:15:14
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.

Exploit
  • EPSS 5.22%
  • Veröffentlicht 06.01.2021 23:15:13
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.

Exploit
  • EPSS 10.38%
  • Veröffentlicht 06.01.2021 23:15:13
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.