[DepShield] (CVSS 10.0) Vulnerability due to usage of com.fasterxml.jackson.core:jackson-databind:2.6.7.1
sonatype-depshield opened this issue · 0 comments
sonatype-depshield commented
Vulnerabilities
DepShield reports that this application's usage of com.fasterxml.jackson.core:jackson-databind:2.6.7.1 results in the following vulnerability(s):
- (CVSS 10.0) [CVE-2018-14721] FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to cond...
- (CVSS 9.8) [CVE-2017-17485] Improper Control of Generation of Code ("Code Injection")
- (CVSS 9.8) [CVE-2019-16335] A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2...
- (CVSS 9.8) [CVE-2018-11307] An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use o...
- (CVSS 9.8) [CVE-2020-9547] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
- (CVSS 9.8) [CVE-2018-14719] Deserialization of Untrusted Data
- (CVSS 9.8) [CVE-2018-14718] Deserialization of Untrusted Data
- (CVSS 9.8) [CVE-2019-17531] A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 th...
- (CVSS 9.8) [CVE-2020-11620] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
- (CVSS 9.8) [CVE-2018-7489] Incomplete Blacklist, Deserialization of Untrusted Data
- (CVSS 9.8) [CVE-2018-19361] Deserialization of Untrusted Data
- (CVSS 9.8) [CVE-2019-20330] FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache bloc...
- (CVSS 9.8) [CVE-2020-9548] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
- (CVSS 9.8) [CVE-2019-14892] A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 an...
- (CVSS 9.8) [CVE-2020-11619] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
- (CVSS 9.8) [CVE-2019-16943] A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 th...
- (CVSS 9.8) [CVE-2019-16942] A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 th...
- (CVSS 9.8) [CVE-2017-15095] Deserialization of Untrusted Data
- (CVSS 9.8) [CVE-2020-8840] FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JN...
- (CVSS 9.8) [CVE-2020-9546] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
- (CVSS 9.8) [CVE-2018-19360] Deserialization of Untrusted Data
- (CVSS 9.8) [CVE-2018-19362] Deserialization of Untrusted Data
- (CVSS 9.8) [CVE-2019-14540] A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2...
- (CVSS 9.8) [CVE-2019-17267] A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2...
- (CVSS 9.8) [CVE-2018-14720] Improper Restriction of XML External Entity Reference ("XXE")
- (CVSS 9.8) [CVE-2019-14893] A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.1...
- (CVSS 8.8) [CVE-2020-10969] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
- (CVSS 8.8) [CVE-2020-10968] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
- (CVSS 8.8) [CVE-2020-10672] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
- (CVSS 8.8) [CVE-2020-10673] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
- (CVSS 8.8) [CVE-2020-11113] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
- (CVSS 8.8) [CVE-2020-11112] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
- (CVSS 8.8) [CVE-2020-11111] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
- (CVSS 8.1) [CVE-2020-35728] FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee...
- (CVSS 8.1) [CVE-2018-5968] Incomplete Blacklist, Deserialization of Untrusted Data
- (CVSS 8.1) [CVE-2020-35491] FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee...
- (CVSS 8.1) [CVE-2020-14062] FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee...
- (CVSS 8.1) [CVE-2020-14061] FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee...
- (CVSS 8.1) [CVE-2020-35490] FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction betwee...
- (CVSS 8.1) [CVE-2020-24750] FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee...
- (CVSS 8.1) [CVE-2020-24616] FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee...
- (CVSS 8.1) [CVE-2020-14060] FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee...
- (CVSS 8.1) [CVE-2020-14195] FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee...
- (CVSS 7.5) [CVE-2019-12086] Information Exposure
- (CVSS 7.5) [CVE-2020-25649] A flaw was found in FasterXML Jackson Databind, where it did not have entity exp...
- (CVSS 5.9) [CVE-2019-12814] Information Exposure
- (CVSS 5.9) [CVE-2019-12384] Deserialization of Untrusted Data
- (CVSS 5.4) CWE-611: Improper Restriction of XML External Entity Reference ('XXE')
Occurrences
com.fasterxml.jackson.core:jackson-databind:2.6.7.1 is a transitive dependency introduced by the following direct dependency(s):
• org.apache.spark:spark-core_2.11:2.3.4
└─ com.fasterxml.jackson.core:jackson-databind:2.6.7.1
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.