Known Vulnerabilities for products from Fasterxml

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Fasterxml".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-20190 A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and ... 8.1 - HIGH 2021-01-19 2023-11-07
CVE-2020-36189 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2021-01-06 2023-09-13
CVE-2020-36188 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2021-01-06 2023-09-13
CVE-2020-36187 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2021-01-06 2023-09-13
CVE-2020-36186 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2021-01-06 2023-09-13
CVE-2020-36185 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2021-01-06 2023-09-13
CVE-2020-36184 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2021-01-06 2023-09-13
CVE-2020-36183 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2021-01-07 2023-09-13
CVE-2020-36182 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2021-01-07 2023-09-13
CVE-2020-36181 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2021-01-06 2023-09-13
CVE-2020-36180 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2021-01-07 2023-09-13
CVE-2020-36179 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2021-01-07 2023-11-07
CVE-2020-35728 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2020-12-27 2023-11-07
CVE-2020-35491 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2020-12-17 2022-09-08
CVE-2020-35490 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2020-12-17 2022-09-08
CVE-2020-28491 This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 a... 7.5 - HIGH 2021-02-18 2022-12-06
CVE-2020-25649 A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vul... 7.5 - HIGH 2020-12-03 2023-11-07
CVE-2020-24750 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2020-09-17 2023-09-13
CVE-2020-24616 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2020-08-25 2023-11-07
CVE-2020-14195 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related t... 8.1 - HIGH 2020-06-16 2021-11-17

Known software with vulnerabilities from Fasterxml

Type Vendor Product Version
ApplicationFasterxmlJackson-
ApplicationFasterxmlJackson-databind2.0.0
ApplicationFasterxmlJackson-dataformat-xml2.0.0
ApplicationFasterxmlJackson-mapper-asl1.9.0
ApplicationFasterxmlJackson-modules-java82.8.5