Known vulnerabilities in jackson-databind (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:jackson-databind_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 20
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting jackson-databind (Debian package) jackson-databind (Debian package) is affected by 20 known vulnerabilities: 7 high, 11 medium, 2 low Critical High Medium Low

Vulnerabilities (20)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU68832 - Resource exhaustion
CVE-2022-42004
CWE-400 Medium
No
No
2.12.1-1+deb11u1 31.10.2022 SB2022103116
SB2022103117
SB2022111404
and 122 more
#VU68635 - Deserialization of Untrusted Data
CVE-2022-42003
CWE-502 Medium
No
No
2.12.1-1+deb11u1 25.10.2022 SB2022102509
SB2022102510
SB2022103117
and 208 more
#VU61799 - Out-of-bounds write
CVE-2020-36518
CWE-787 Medium
No
No
2.12.1-1+deb11u1 01.04.2022 SB2022040113
SB2022040114
SB2022040115
and 147 more
#VU21593 - Improper input validation
CVE-2019-16943
CWE-20 Medium
No
No
2.8.6-1+deb9u6, 2.9.8-3+deb10u1 07.10.2019 SB2019100711
SB2019100716
SB2019120206
and 34 more
#VU21580 - Improper input validation
CVE-2019-16942
CWE-20 Medium
No
No
2.8.6-1+deb9u6, 2.9.8-3+deb10u1 07.10.2019 SB2019100711
SB2019100716
SB2019111903
and 23 more
#VU21136 - Exposure of sensitive information to an unauthorized actor
CVE-2019-16335
CWE-200 Medium
No
No
2.8.6-1+deb9u6, 2.9.8-3+deb10u1 16.09.2019 SB2019091616
SB2019100716
SB2019102422
and 21 more
#VU21135 - Exposure of sensitive information to an unauthorized actor
CVE-2019-14540
CWE-200 Medium
Available
No
2.8.6-1+deb9u6, 2.9.8-3+deb10u1 16.09.2019 SB2019091616
SB2019100716
SB2019102422
and 23 more
#VU19943 - Deserialization of Untrusted Data
CVE-2018-12023
CWE-502 Medium
No
No
2.8.6-1+deb9u5 06.08.2019 SB2019052407
SB2019091718
SB2019092703
and 20 more
#VU19942 - Deserialization of Untrusted Data
CVE-2018-12022
CWE-502 Medium
No
No
2.8.6-1+deb9u5 06.08.2019 SB2019052407
SB2019091718
SB2019092703
and 18 more
#VU19941 - Exposure of sensitive information to an unauthorized actor
CVE-2019-12086
CWE-200 Medium
No
No
2.8.6-1+deb9u5 06.08.2019 SB2019052407
SB2019092703
SB2019100116
and 29 more
#VU19938 - Deserialization of Untrusted Data
CVE-2018-11307
CWE-502 High
No
No
2.8.6-1+deb9u5 06.08.2019 SB2019052407
SB2019091718
SB2019092703
and 17 more
#VU19937 - Exposure of sensitive information to an unauthorized actor
CVE-2019-14439
CWE-200 Medium
No
No
2.8.6-1+deb9u6, 2.9.8-3+deb10u1 06.08.2019 SB2019073015
SB2019100716
SB2019102422
and 16 more
#VU19018 - Deserialization of Untrusted Data
CVE-2019-12384
CWE-502 High
No
No
2.8.6-1+deb9u6, 2.9.8-3+deb10u1 04.07.2019 SB2019091218
SB2019092703
SB2019100116
and 28 more
#VU17781 - Improper input validation
CVE-2018-19362
CWE-20 High
No
No
2.8.6-1+deb9u5 19.02.2019 SB2018121501
SB2019052407
SB2019091718
and 38 more
#VU17780 - Improper input validation
CVE-2018-19360
CWE-20 High
No
No
2.8.6-1+deb9u5 19.02.2019 SB2018121501
SB2019052407
SB2019091718
and 22 more
#VU17779 - Improper input validation
CVE-2018-19361
CWE-20 High
No
No
2.8.6-1+deb9u5 19.02.2019 SB2018121501
SB2019052407
SB2019091718
and 23 more
#VU17778 - Improper input validation
CVE-2018-14719
CWE-20 High
No
No
2.8.6-1+deb9u5 19.02.2019 SB2018121501
SB2019052407
SB2019091718
and 22 more
#VU17777 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2018-14720
CWE-611 Low
No
No
2.8.6-1+deb9u5 19.02.2019 SB2018121501
SB2019052407
SB2019092703
and 21 more
#VU17776 - Server-Side Request Forgery (SSRF)
CVE-2018-14721
CWE-918 Low
No
No
2.8.6-1+deb9u5 19.02.2019 SB2018121501
SB2019052407
SB2019092703
and 23 more
#VU17053 - Permissions, Privileges, and Access Controls
CVE-2018-14718
CWE-264 High
No
No
2.8.6-1+deb9u5 17.01.2019 SB2019011703
SB2019052407
SB2019091718
and 29 more