Serialization Vulnerability in Jackson-Databind Affects FasterXML
CVE-2020-35490
8.1HIGH
What is CVE-2020-35490?
This vulnerability arises in the jackson-databind library, specifically affecting versions prior to 2.9.10.8. It involves a mishandling of serialization processes between specific gadgets and data types, notably concerning the org.apache.commons.dbcp2.datasources.PerUserPoolDataSource. Exploitation of this vulnerability could potentially allow malicious actors to execute unauthorized operations within applications relying on this library. Developers are advised to upgrade to the latest version to mitigate associated risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
