CVE-2020-35490: High severity fasterxml jackson-databind vulnerability
A flaw was found in jackson-databind. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.10.8 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.10.8
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-35490?
CVE-2020-35490 is a vulnerability in the FasterXML jackson-databind library that allows a remote attacker to execute arbitrary code on the system through unsafe deserialization.
How does CVE-2020-35490 impact the system?
CVE-2020-35490 allows an attacker to execute arbitrary code on the affected system.
What is the severity level of CVE-2020-35490?
CVE-2020-35490 has a severity level of 8.1 (high).
Which software versions are affected by CVE-2020-35490?
CVE-2020-35490 affects FasterXML jackson-databind versions up to and excluding 2.9.10.8.
How can I fix CVE-2020-35490?
To fix CVE-2020-35490, you need to upgrade FasterXML jackson-databind to version 2.9.10.8 or later.