FasterXML Jackson Databind 代码问题漏洞

admin 2024-01-15 15:32:21 YS 来源:ZONE.CI 全球网 0 阅读模式
> FasterXML Jackson Databind 代码问题漏洞

FasterXML Jackson Databind 代码问题漏洞

CNNVD-ID编号 CNNVD-202010-622 CVE编号 CVE-2020-25649
发布时间 2020-10-14 更新时间 2021-01-18
漏洞类型 代码问题 漏洞来源 N/A
危险等级 高危 威胁类型 远程
厂商 N/A

漏洞介绍

FasterXML jackson-databind是一个基于JAVA可以将XML和JSON等数据格式与JAVA对象进行转换的库。Jackson可以轻松的将Java对象转换成json对象和xml文档,同样也可以将json、xml转换成Java对象。

FasterXML Jackson Databind存在代码问题漏洞,攻击者可利用该漏洞可以将恶意的XML数据传输到FasterXML Jackson Databind,以读取文件、扫描站点或触发拒绝服务。

漏洞补丁

目前厂商已发布升级了FasterXML Jackson Databind 代码问题漏洞的补丁,FasterXML Jackson Databind 代码问题漏洞的补丁获取链接:

参考网址

来源:MLIST

链接:https://lists.apache.org/thread.html/r0b8dc3acd4503e4ecb6fbd6ea7d95f59941168d8452ac0ab1d1d96bb@%3Cissues.zookeeper.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r94c7e86e546120f157264ba5ba61fd29b3a8d530ed325a9b4fa334d7@%3Ccommits.zookeeper.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/ra1157e57a01d25e36b0dc17959ace758fc21ba36746de29ba1d8b130@%3Cjira.kafka.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/rc959cdb57c4fe198316130ff4a5ecbf9d680e356032ff2e9f4f05d54@%3Cjira.kafka.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/rd317f15a675d114dbf5b488d27eeb2467b4424356b16116eb18a652d@%3Cjira.kafka.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/rb674520b9f6c808c1bf263b1369e14048ec3243615f35cfd24e33604@%3Cissues.zookeeper.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r2882fc1f3032cd7be66e28787f04ec6f1874ac68d47e310e30ff7eb1@%3Cjira.kafka.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/rc88f2fa2b7bd6443921727aeee7704a1fb02433e722e2abf677e0d3d@%3Ccommits.zookeeper.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/rd6f6bf848c2d47fa4a85c27d011d948778b8f7e58ba495968435a0b3@%3Cissues.zookeeper.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080@%3Cusers.kafka.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080@%3Cdev.kafka.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/raf13235de6df1d47a717199e1ecd700dff3236632f5c9a1488d9845b@%3Cjira.kafka.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r04529cedaca40c2ff90af4880493f9c88a8ebf4d1d6c861d23108a5a@%3Cnotifications.zookeeper.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r86c78bf7656fdb2dab69cbf17f3d7492300f771025f1a3a65d5e5ce5@%3Ccommits.zookeeper.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r1b7ed0c4b6c4301d4dfd6fdbc5581b0a789d3240cab55d766f33c6c6@%3Cjira.kafka.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304@%3Cdev.kafka.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/rdf9a34726482222c90d50ae1b9847881de67dde8cfde4999633d2cdc@%3Ccommits.zookeeper.apache.org%3E

来源:MISC

链接:https://bugzilla.redhat.com/show_bug.cgi?id=1887664

来源:MISC

链接:https://lists.apache.org/thread.html/r31f4ee7d561d56a0c2c2c6eb1d6ce3e05917ff9654fdbfec05dc2b83@%3Ccommits.servicecomb.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r6e3d4f7991542119a4ca6330271d7fbf7b9fb3abab24ada82ddf1ee4@%3Cnotifications.zookeeper.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r2b6ddb3a4f4cd11d8f6305011e1b7438ba813511f2e3ab3180c7ffda@%3Ccommits.druid.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304@%3Cusers.kafka.apache.org%3E

来源:MISC

链接:https://github.com/FasterXML/jackson-databind/issues/2589

来源:MLIST

链接:https://lists.apache.org/thread.html/r5f8a1608d758936bd6bbc5eed980777437b611537bf6fff40663fc71@%3Cjira.kafka.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r90d1e97b0a743cf697d89a792a9b669909cc5a1692d1e0083a22e66c@%3Cissues.zookeeper.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r63c87aab97155f3f3cbe11d030c4a184ea0de440ee714977db02e956@%3Cjira.kafka.apache.org%3E

来源:CONFIRM

链接:https://security.netapp.com/advisory/ntap-20210108-0007/

来源:MLIST

链接:https://lists.apache.org/thread.html/r78d53a0a269c18394daf5940105dc8c7f9a2399503c2e78be20abe7e@%3Cjira.kafka.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r900d4408c4189b376d1ec580ea7740ea6f8710dc2f0b7e9c9eeb5ae0@%3Cdev.zookeeper.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/rc15e90bbef196a5c6c01659e015249d6c9a73581ca9afb8aeecf00d2@%3Cjira.kafka.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r98bfe3b90ea9408f12c4b447edcb5638703d80bc782430aa0c210a54@%3Cissues.zookeeper.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/r68d029ee74ab0f3b0569d0c05f5688cb45dd3abe96a6534735252805@%3Cnotifications.zookeeper.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.html/re96dc7a13e13e56190a5d80f9e5440a0d0c83aeec6467b562fbf2dca@%3Cjira.kafka.apache.org%3E

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.3537/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.3943/

来源:nvd.nist.gov

链接:https://nvd.nist.gov/vuln/detail/CVE-2020-25649

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.3705/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/160346/Red-Hat-Security-Advisory-2020-5344-01.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.4286/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.4451/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/159680/Red-Hat-Security-Advisory-2020-4312-01.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/159759/Red-Hat-Security-Advisory-2020-4402-01.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.4405/

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/160535/Red-Hat-Security-Advisory-2020-5533-01.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/159973/Red-Hat-Security-Advisory-2020-4379-01.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/160489/Red-Hat-Security-Advisory-2020-5410-01.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.3652/

受影响实体

暂无

信息来源

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202010-622

weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论:0   参与:  0