SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-20190

The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

HIGH 8.1EPSS 7.48%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (7.48%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
7.48% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-502
Affected
fasterxml/jackson-databind · netapp/active iq unified manager · netapp/oncommand api services · netapp/oncommand insight · netapp/service level manager · apache/nifi · debian/debian linux · oracle/commerce experience manager · oracle/commerce guided search
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.