CVE-2020-24750
jackson-databind, agile product lifecycle management
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
- CVSS
- 8.1
- EPSS
- 7.33% 94.0% percentile
- CISA KEV
- Not listed
- Published
- 2020.09.18