VDB
BDU%3A2020-00566
BDU%3A2020-00566
PUBLISHED
CVSS 10 CRITICAL
Уязвимость реализации механизма полиморфной типизации данных библиотеки FasterXML Jackson-databind, позволяющая нарушителю получить полный контроль над приложением
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., Сообщество свободного программного обеспечения, Oracle Corp., ООО «РусБИТех-Астра», Red Hat Inc., FasterXML, LLC, Apache Software Foundation, АО «НТЦ ИТ РОСА», АО «Концерн ВНИИНС» | Ubuntu, Debian GNU/Linux, WebCenter Portal, WebLogic Server, Astra Linux Common Edition (запись в едином реестре российских программ №4433), Red Hat JBoss Fuse, Retail Customer Management and Segmentation Foundation, JBoss Enterprise Application Platform, Jackson-databind, JBoss Data Grid, OpenShift Application Runtimes, Red Hat Process Automation Manager, Drill, Red Hat AMQ Streams, Red Hat Single Sign-On, OpenShift Container Platform, Red Hat Descision Manager, Oracle GoldenGate Application Adapters, РОСА ХРОМ (запись в едином реестре российских программ №1607), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Feb 11, 2020 CVE Published
- Mar 5, 2025 CVE Updated
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
References
- https://www.oracle.com/security-alerts/cpujul2020.html url
- https://access.redhat.com/errata/RHSA-2019:3200 url
- https://access.redhat.com/errata/RHSA-2020:0159 url
- https://access.redhat.com/errata/RHSA-2020:0160 url
- https://access.redhat.com/errata/RHSA-2020:0161 url
- https://access.redhat.com/errata/RHSA-2020:0164 url
- https://access.redhat.com/errata/RHSA-2020:0445 url
- https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.3...jackson-databind-2.9.10 url
- https://github.com/FasterXML/jackson-databind/issues/2460 url
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E url
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E url
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E url
- https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E url
- https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html url
- https://security.netapp.com/advisory/ntap-20191017-0006/ url
- https://www.oracle.com/security-alerts/cpujan2020.html url
- https://www.oracle.com/security-alerts/cpuoct2020.html url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2629 url
- https://access.redhat.com/security/cve/CVE-2019-17267 advisory
…and 2 more