| CNNVD-ID编号 | CNNVD-201907-1434 |
| CVE编号 | CVE-2019-14379 |
| 发布时间 | 2019-07-29 |
| 更新时间 | 2020-10-21 |
| 漏洞类型 | 输入验证错误 |
| 漏洞来源 | N/A |
| 危险等级 | 超危 |
| 威胁类型 | 远程 |
| 厂 商 | N/A |
FasterXML Jackson是美国FasterXML公司的一款适用于Java的数据处理工具。jackson-databind是其中的一个具有数据绑定功能的组件。
FasterXML jackson-databind 2.9.9.2之前版本中的SubTypeValidator.java文件存在输入验证错误漏洞。攻击者可利用该漏洞执行代码。
目前厂商已发布升级了FasterXML jackson-databind 输入验证错误漏洞的补丁,FasterXML jackson-databind 输入验证错误漏洞的补丁获取链接:
https://github.com/FasterXML/jackson-databind/issues/2387
来源:MISC
链接:https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
来源:REDHAT
来源:MLIST
来源:www.oracle.com
来源:REDHAT
来源:MISC
来源:MLIST
来源:MLIST
来源:REDHAT
来源:REDHAT
来源:REDHAT
来源:MLIST
来源:MLIST
来源:MLIST
来源:MLIST
来源:MLIST
来源:MLIST
来源:MLIST
来源:FEDORA
来源:MLIST
来源:REDHAT
来源:REDHAT
来源:MLIST
来源:N/A
来源:MLIST
来源:REDHAT
来源:MLIST
来源:REDHAT
来源:REDHAT
来源:REDHAT
来源:REDHAT
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html
来源:MLIST
来源:MLIST
来源:REDHAT
来源:MLIST
来源:MLIST
来源:MLIST
来源:CONFIRM
来源:MLIST
来源:MISC
来源:MLIST
来源:MLIST
来源:MLIST
来源:FEDORA
来源:REDHAT
来源:MISC
链接:https://github.com/FasterXML/jackson-databind/issues/2387
来源:REDHAT
来源:REDHAT
来源:MLIST
来源:FEDORA
来源:REDHAT
来源:REDHAT
来源:MLIST
来源:MLIST
来源:MISC
来源:lists.debian.org
链接:https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html
来源:www.ibm.com
来源:www.ibm.com
来源:access.redhat.com
来源:access.redhat.com
来源:access.redhat.com
来源:access.redhat.com
来源:www.ibm.com
来源:access.redhat.com
来源:access.redhat.com
来源:www.ibm.com
来源:access.redhat.com
来源:www.oracle.com
来源:www.auscert.org.au
来源:nvd.nist.gov
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/155382/Red-Hat-Security-Advisory-2019-3901-01.html
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujan2020verbose.html
来源:www.ibm.com
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/154469/Red-Hat-Security-Advisory-2019-2743-01.html
来源:www.auscert.org.au
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/jackson-databind-code-execution-via-SubTypeValidator-30021
来源:www.ibm.com
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156941/Red-Hat-Security-Advisory-2020-0983-01.html
来源:www.ibm.com
来源:www.auscert.org.au
来源:www.nsfocus.net
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.ibm.com
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.ibm.com
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156628/Red-Hat-Security-Advisory-2020-0727-01.html
来源:www.auscert.org.au
暂无