CVE-2021-20190

Source
https://cve.org/CVERecord?id=CVE-2021-20190
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-20190.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-20190
Aliases
Downstream
Related
Published
2021-01-19T17:15:13.427Z
Modified
2026-05-18T05:51:17.616062116Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "CPE_FIELD",
            "cpes": [
                "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "last_affected": "9.0"
                }
            ],
            "vendor_product": "debian:debian_linux"
        },
        {
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "last_affected": "11.3.2"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:commerce_guided_search_and_experience_manager:11.3.2:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:commerce_guided_search_and_experience_manager"
        }
    ]
}
References

Affected packages

Git / github.com/apache/nifi

Affected ranges

Type
GIT
Repo
https://github.com/apache/nifi
Events
Database specific
{
    "cpe": "cpe:2.3:a:apache:nifi:*:*:*:*:*:*:*:*",
    "source": "CPE_FIELD",
    "extracted_events": [
        {
            "introduced": "1.7.0"
        },
        {
            "last_affected": "1.12.1"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-20190.json"

Git / github.com/fasterxml/jackson-databind

Affected ranges

Type
GIT
Repo
https://github.com/fasterxml/jackson-databind
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*",
    "source": "CPE_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.6.7.5"
        },
        {
            "introduced": "2.7.0"
        },
        {
            "fixed": "2.9.10.7"
        }
    ]
}

Affected versions

2.*
2.2.0c
2.6.0-rc3b
jackson-databind-2.*
jackson-databind-2.0.0
jackson-databind-2.0.0-RC1
jackson-databind-2.0.0-RC2
jackson-databind-2.0.0-RC3
jackson-databind-2.0.1
jackson-databind-2.0.2
jackson-databind-2.1.0
jackson-databind-2.1.1
jackson-databind-2.2.0
jackson-databind-2.2.1
jackson-databind-2.2.2
jackson-databind-2.3.0
jackson-databind-2.3.0-rc1
jackson-databind-2.3.1
jackson-databind-2.4.0
jackson-databind-2.4.0-rc1
jackson-databind-2.4.0-rc2
jackson-databind-2.4.0-rc3
jackson-databind-2.4.1
jackson-databind-2.4.1.1
jackson-databind-2.4.1.2
jackson-databind-2.4.1.3
jackson-databind-2.5.0
jackson-databind-2.5.0-rc1
jackson-databind-2.6.0
jackson-databind-2.6.0-rc1
jackson-databind-2.6.0-rc4
jackson-databind-2.6.1
jackson-databind-2.6.2
jackson-databind-2.6.3
jackson-databind-2.6.4
jackson-databind-2.6.5
jackson-databind-2.6.6
jackson-databind-2.6.7
jackson-databind-2.6.7.1
jackson-databind-2.6.7.2
jackson-databind-2.6.7.3
jackson-databind-2.6.7.4
jackson-databind-2.7.0
jackson-databind-2.7.1
jackson-databind-2.7.1-1
jackson-databind-2.8.0
jackson-databind-2.8.1
jackson-databind-2.8.2
jackson-databind-2.9.0
jackson-databind-2.9.0.pr1
jackson-databind-2.9.0.pr2
jackson-databind-2.9.0.pr3
jackson-databind-2.9.0.pr4
jackson-databind-2.9.1
jackson-databind-2.9.10
jackson-databind-2.9.10.1
jackson-databind-2.9.10.2
jackson-databind-2.9.10.3
jackson-databind-2.9.10.4
jackson-databind-2.9.10.5
jackson-databind-2.9.10.6
jackson-databind-2.9.3
jackson-databind-2.9.4
jackson-databind-2.9.5
jackson-databind-2.9.6
jackson-databind-2.9.7
jackson-databind-2.9.8
jackson-databind-2.9.9
jackson-databind-2.9.9.1
jackson-databind-2.9.9.2
jackson-databind-2.9.9.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-20190.json"