{"schema_version":"1.9.0","id":"GHSA-5949-rw7g-wx7w","published":"2021-01-20T21:20:15Z","modified":"2025-09-15T07:42:14.888352Z","aliases":["BIT-nifi-2021-20190","CVE-2021-20190"],"summary":"Deserialization of untrusted data in jackson-databind","details":"A flaw was found in jackson-databind before 2.9.10.7 and 2.6.7.5. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.","affected":[{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","ecosystem":"Maven","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.7.0"},{"fixed":"2.9.10.7"}]}],"versions":["2.7.0","2.7.1","2.7.1-1","2.7.2","2.7.3","2.7.4","2.7.5","2.7.6","2.7.7","2.7.8","2.7.9","2.7.9.1","2.7.9.2","2.7.9.3","2.7.9.4","2.7.9.5","2.7.9.6","2.7.9.7","2.8.0","2.8.0.rc1","2.8.0.rc2","2.8.1","2.8.10","2.8.11","2.8.11.1","2.8.11.2","2.8.11.3","2.8.11.4","2.8.11.5","2.8.11.6","2.8.2","2.8.3","2.8.4","2.8.5","2.8.6","2.8.7","2.8.8","2.8.8.1","2.8.9","2.9.0","2.9.0.pr1","2.9.0.pr2","2.9.0.pr3","2.9.0.pr4","2.9.1","2.9.10","2.9.10.1","2.9.10.2","2.9.10.3","2.9.10.4","2.9.10.5","2.9.10.6","2.9.2","2.9.3","2.9.4","2.9.5","2.9.6","2.9.7","2.9.8","2.9.9","2.9.9.1","2.9.9.2","2.9.9.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/01/GHSA-5949-rw7g-wx7w/GHSA-5949-rw7g-wx7w.json"}},{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","ecosystem":"Maven","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.7.5"}]}],"versions":["2.0.0","2.0.0-RC1","2.0.0-RC2","2.0.0-RC3","2.0.1","2.0.2","2.0.4","2.0.5","2.0.6","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.2.0","2.2.0-rc1","2.2.1","2.2.2","2.2.3","2.2.4","2.3.0","2.3.0-rc1","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.4.0","2.4.0-rc1","2.4.0-rc2","2.4.0-rc3","2.4.1","2.4.1.1","2.4.1.2","2.4.1.3","2.4.2","2.4.3","2.4.4","2.4.5","2.4.5.1","2.4.6","2.4.6.1","2.5.0","2.5.0-rc1","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6.0","2.6.0-rc1","2.6.0-rc2","2.6.0-rc3","2.6.0-rc4","2.6.1","2.6.2","2.6.3","2.6.4","2.6.5","2.6.6","2.6.7","2.6.7.1","2.6.7.2","2.6.7.3","2.6.7.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/01/GHSA-5949-rw7g-wx7w/GHSA-5949-rw7g-wx7w.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-20190"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/issues/2854"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88"},{"type":"WEB","url":"https://github.com/FasterXML/jackson-databind/commit/7dbf51bf78d157098074a20bd9da39bd48c18e4a"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1916633"},{"type":"PACKAGE","url":"https://github.com/FasterXML/jackson-databind"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r380e9257bacb8551ee6fcf2c59890ae9477b2c78e553fa9ea08e9d9a@%3Ccommits.nifi.apache.org%3E"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20210219-0008"},{"type":"WEB","url":"https://www.oracle.com//security-alerts/cpujul2021.html"}],"database_specific":{"cwe_ids":["CWE-502"],"github_reviewed":true,"github_reviewed_at":"2021-01-20T04:44:51Z","nvd_published_at":"2021-01-19T17:15:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}