- 
          
 - 
                Notifications
    
You must be signed in to change notification settings  - Fork 1.4k
 
Closed
Labels
CVEIssues related to public CVEs (security vuln reports)Issues related to public CVEs (security vuln reports)
Milestone
Description
Another 2 gadget (*) types reported related to JNDI access.
See https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 for description of the general problem.
Mitre id: CVE-2019-20330
Original discoverer: UltramanGaia
Fixed in:
- 2.9.10.2 (
jackson-bomversion2.9.10.20200223) - 2.8.11.5 (
jackson-bomversion2.8.11.20200210) - 2.7.9.7
 - does not affect 2.10.0 and later
 
melloware, jdelta-RBS, vhalthi and vineethNaroju
Metadata
Metadata
Assignees
Labels
CVEIssues related to public CVEs (security vuln reports)Issues related to public CVEs (security vuln reports)