VDB

CVE-2020-24750

CVE-2020-24750 PUBLISHED

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.

EPSS 2.05% · 84.2th percentile

Risk Scores

EPSS Score
2.05%
84.2th percentile

Affected Products

VendorProductVersions
AWSconfig
Ubuntu:25.10jackson-databind2.14.0+ds-1, 0
Ubuntu:18.04:LTSjackson-databind2.9.5-1, 2.8.6-1, 0
Ubuntu:Pro:16.04:LTSjackson-databind0, 2.4.2-3ubuntu0.1~esm1, 2.4.2-3ubuntu0.1~esm2
Ubuntu:24.04:LTSjackson-databind0, 2.14.0-1
Ubuntu:22.04:LTSjackson-databind2.13.0-2, 2.12.1-1, 0
Ubuntu:20.04:LTSjackson-databind2.10.1-1, 2.10.2-1, 2.10.0-2
Ubuntu:Pro:14.04:LTSjackson-databind0, 2.2.2-1ubuntu0.1~esm1, 2.2.2-1

Exploit Intelligence

…and 24 more exploits

Timeline

  • CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 15, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 21, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 8, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›