VDB

BDU%3A2019-02925

BDU%3A2019-02925 PUBLISHED CVSS 7.099999904632568 HIGH

Уязвимость класса logback-core библиотеки Jackson-databind, позволяющая нарушителю выполнить произвольный код

Risk Scores

CVSS 2.0
7.099999904632568

Affected Products

VendorProductVersions
Сообщество свободного программного обеспечения, Novell Inc., Fedora Project, ООО «РусБИТех-Астра», Red Hat Inc., FasterXML, LLC, Oracle Corp., АО «Концерн ВНИИНС»Debian GNU/Linux, OpenSUSE Leap, Fedora, Astra Linux Common Edition (запись в едином реестре российских программ №4433), Red Hat Enterprise Linux, Red Hat JBoss Fuse, Jackson-databind, Retail Customer Management and Segmentation Foundation, JBoss A-MQ, OpenShift Application Runtimes, NoSQL Database, Red Hat Process Automation Manager, Red Hat AMQ Streams, JBoss Enterprise Application Platform, Red Hat Descision Manager, Red Hat JBoss EAP, GoldenGate Stream Analytics, ОС ОН «Стрелец» (запись в едином реестре российских программ №6177)

Timeline

  • Aug 20, 2019 CVE Published
  • Nov 21, 2023 CVE Updated
  • Mar 18, 2026 Distribution Patch
  • Mar 18, 2026 Distribution Patch
  • Mar 18, 2026 Distribution Patch
  • Mar 18, 2026 Distribution Patch
  • Mar 18, 2026 Security Advisory
  • Mar 23, 2026 Distribution Patch
  • Mar 23, 2026 Distribution Patch
  • Mar 23, 2026 Distribution Patch
  • Mar 23, 2026 Distribution Patch
  • Mar 23, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›