diff options
author | Moritz Muehlenhoff <jmm@debian.org> | 2021-01-18 16:01:28 +0100 |
---|---|---|
committer | Moritz Muehlenhoff <jmm@debian.org> | 2021-01-18 16:01:28 +0100 |
commit | c932a5e0315f414b9d1669a4ee78c24c9e2787b6 (patch) | |
tree | 0f93373c3013be4c241e0e8d5f26b9c360d050bd | |
parent | 900116bebfca7cd15183a046ad8691fb6c6abf50 (diff) |
jackson-databind fixed in sid (first batch)
-rw-r--r-- | data/CVE/list | 12 |
1 files changed, 8 insertions, 4 deletions
diff --git a/data/CVE/list b/data/CVE/list index d38c3b4f8c..5176523988 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -5349,33 +5349,37 @@ CVE-2021-22698 CVE-2021-22697 RESERVED CVE-2020-36189 (FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interact ...) - - jackson-databind <unfixed> + - jackson-databind 2.12.1-1 [buster] - jackson-databind <no-dsa> (Minor issue) [stretch] - jackson-databind <no-dsa> (Minor issue) NOTE: https://github.com/FasterXML/jackson-databind/issues/2996 NOTE: Starting from 2.10 series mitigated as Safe Default Typing is enabled by default NOTE: but still an issue when Default Typing is enabled. + NOTE: https://github.com/FasterXML/jackson-databind/commit/33d96c13fe18a2dad01b19ce195548c9acea9da4 CVE-2020-36188 (FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interact ...) - - jackson-databind <unfixed> + - jackson-databind 2.12.1-1 [buster] - jackson-databind <no-dsa> (Minor issue) [stretch] - jackson-databind <no-dsa> (Minor issue) NOTE: https://github.com/FasterXML/jackson-databind/issues/2996 NOTE: Starting from 2.10 series mitigated as Safe Default Typing is enabled by default NOTE: but still an issue when Default Typing is enabled. + NOTE: https://github.com/FasterXML/jackson-databind/commit/33d96c13fe18a2dad01b19ce195548c9acea9da4 CVE-2020-36187 (FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interact ...) - - jackson-databind <unfixed> + - jackson-databind 2.12.1-1 [buster] - jackson-databind <no-dsa> (Minor issue) [stretch] - jackson-databind <no-dsa> (Minor issue) NOTE: https://github.com/FasterXML/jackson-databind/issues/2997 NOTE: Starting from 2.10 series mitigated as Safe Default Typing is enabled by default NOTE: but still an issue when Default Typing is enabled. + NOTE: https://github.com/FasterXML/jackson-databind/commit/3e8fa3beea49ea62109df9e643c9cb678dabdde1 CVE-2020-36186 (FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interact ...) - - jackson-databind <unfixed> + - jackson-databind 2.12.1-1 [buster] - jackson-databind <no-dsa> (Minor issue) [stretch] - jackson-databind <no-dsa> (Minor issue) NOTE: https://github.com/FasterXML/jackson-databind/issues/2997 NOTE: Starting from 2.10 series mitigated as Safe Default Typing is enabled by default NOTE: but still an issue when Default Typing is enabled. + NOTE: https://github.com/FasterXML/jackson-databind/commit/3e8fa3beea49ea62109df9e643c9cb678dabdde1 CVE-2020-36185 (FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interact ...) - jackson-databind <unfixed> [buster] - jackson-databind <no-dsa> (Minor issue) |