VDB
BDU%3A2024-00181
BDU%3A2024-00181
PUBLISHED
CVSS 7.599999904632568 HIGH
Уязвимость библиотеки jackson-databind проекта FasterXML, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
7.599999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, NetApp Inc., Novell Inc., Red Hat Inc., FasterXML, LLC, АО "НППКТ", АО «НТЦ ИТ РОСА», Oracle Corp. | Debian GNU/Linux, Oncommand Insight, openSUSE Tumbleweed, Red Hat OpenStack Platform, Red Hat JBoss Data Virtualization, Red Hat BPM Suite, OpenSUSE Leap, SUSE Linux Enterprise Module for Development Tools, Suse Linux Enterprise Server, Red Hat JBoss BRMS, Red Hat JBoss Fuse Service Works, OpenShift Logging, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Server for SAP Applications, SUSE Manager Proxy, SUSE Manager Server, Suse Linux Enterprise Desktop, SUSE Enterprise Storage, SUSE Manager Retail Branch Server, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Red Hat OpenShift Container Platform, Service Level Manager (SLM), SUSE Linux Enterprise Module for Basesystem, Jackson-databind, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), РОСА ХРОМ (запись в едином реестре российских программ №1607), Active IQ Unified Manager for Linux, NetApp Cloud Backup (formerly AltaVault), OnCommand API Services, Commerce Experience Manager |
Timeline
- Jan 11, 2024 CVE Published
- Mar 5, 2025 CVE Updated
References
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2629 url
- https://github.com/FasterXML/jackson-databind/issues/2854 advisory
- https://security-tracker.debian.org/tracker/CVE-2021-20190 url
- https://access.redhat.com/security/cve/CVE-2021-20190 url
- https://www.suse.com/security/cve/CVE-2021-20190.html url
- https://security.netapp.com/advisory/ntap-20210219-0008/ url
- https://www.oracle.com/security-alerts/cpujul2021.html url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.1/ url