Serialization Gadget Mismanagement in FasterXML Jackson Library
CVE-2020-14062

8.1HIGH

Key Information:

Vendor

Fasterxml

Vendor
CVE Published:
14 June 2020

What is CVE-2020-14062?

The FasterXML Jackson library is susceptible to issues stemming from mishandling the interaction between serialization gadgets and typing, specifically linked to the JNDIConnectionPool in the xalan2 library. This vulnerability allows attackers to potentially exploit insecure object deserialization, leading to unauthorized actions and data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

EPSS Score

7% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.