Bugzilla – Bug 1168207
VUL-1: CVE-2020-11111: jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.*
Last modified: 2020-03-31 14:59:02 UTC
CVE-2020-11111 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms). References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-11111 https://github.com/FasterXML/jackson-databind/issues/2664 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11111 https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
shipping 2.10.2, which is not affected