CVE-2022-42003
- EPSS 2.77%
- Veröffentlicht 02.10.2022 05:15:09
- Zuletzt bearbeitet 07.10.2026 17:16:43
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enab...
CVE-2022-42004
- EPSS 2.77%
- Veröffentlicht 02.10.2022 05:15:09
- Zuletzt bearbeitet 07.10.2026 17:16:43
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choice...
CVE-2020-36518
- EPSS 4.86%
- Veröffentlicht 11.03.2022 07:15:07
- Zuletzt bearbeitet 27.08.2025 21:15:36
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
CVE-2021-20190
- EPSS 7.48%
- Veröffentlicht 19.01.2021 17:15:13
- Zuletzt bearbeitet 24.07.2026 14:27:51
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2020-36183
- EPSS 4.89%
- Veröffentlicht 07.01.2021 00:15:15
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.
CVE-2020-36182
- EPSS 5.02%
- Veröffentlicht 07.01.2021 00:15:14
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36180
- EPSS 5.04%
- Veröffentlicht 07.01.2021 00:15:14
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36179
- EPSS 20.93%
- Veröffentlicht 07.01.2021 00:15:14
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36186
- EPSS 5.22%
- Veröffentlicht 06.01.2021 23:15:13
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.
CVE-2020-36184
- EPSS 10.38%
- Veröffentlicht 06.01.2021 23:15:13
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.