-
-
Notifications
You must be signed in to change notification settings - Fork 1.4k
Closed
Labels
CVEIssues related to public CVEs (security vuln reports)Issues related to public CVEs (security vuln reports)
Milestone
Description
Another gadget type(s) reported regarding a class of caucho-quercus
library.
See https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 for description of the general problem.
Mitre id: CVE-2020-10673
Reporter: threedr3am'follower
Fix is included in:
- 2.9.10.4
- 2.6.7.4 (see https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.6.7.x)
- Does not affect 2.10.0 and later
Metadata
Metadata
Assignees
Labels
CVEIssues related to public CVEs (security vuln reports)Issues related to public CVEs (security vuln reports)