← Back to browse · API

CVE-2020-36179

Severity
HIGH
CVSS
8.8
EPSS
0.20929
Risk score
42.53
CISA KEV
No
PoC
No
Published
2021-01-06
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2021-2495, GHSA-9GPH-22XH-8X98
Products
n/a:n/a n/a
Sources
euvd EUVD-2021-2495

Description

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.

References