From c932a5e0315f414b9d1669a4ee78c24c9e2787b6 Mon Sep 17 00:00:00 2001 From: Moritz Muehlenhoff Date: Mon, 18 Jan 2021 16:01:28 +0100 Subject: jackson-databind fixed in sid (first batch) --- data/CVE/list | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/data/CVE/list b/data/CVE/list index d38c3b4f8c..5176523988 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -5349,33 +5349,37 @@ CVE-2021-22698 CVE-2021-22697 RESERVED CVE-2020-36189 (FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interact ...) - - jackson-databind + - jackson-databind 2.12.1-1 [buster] - jackson-databind (Minor issue) [stretch] - jackson-databind (Minor issue) NOTE: https://github.com/FasterXML/jackson-databind/issues/2996 NOTE: Starting from 2.10 series mitigated as Safe Default Typing is enabled by default NOTE: but still an issue when Default Typing is enabled. + NOTE: https://github.com/FasterXML/jackson-databind/commit/33d96c13fe18a2dad01b19ce195548c9acea9da4 CVE-2020-36188 (FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interact ...) - - jackson-databind + - jackson-databind 2.12.1-1 [buster] - jackson-databind (Minor issue) [stretch] - jackson-databind (Minor issue) NOTE: https://github.com/FasterXML/jackson-databind/issues/2996 NOTE: Starting from 2.10 series mitigated as Safe Default Typing is enabled by default NOTE: but still an issue when Default Typing is enabled. + NOTE: https://github.com/FasterXML/jackson-databind/commit/33d96c13fe18a2dad01b19ce195548c9acea9da4 CVE-2020-36187 (FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interact ...) - - jackson-databind + - jackson-databind 2.12.1-1 [buster] - jackson-databind (Minor issue) [stretch] - jackson-databind (Minor issue) NOTE: https://github.com/FasterXML/jackson-databind/issues/2997 NOTE: Starting from 2.10 series mitigated as Safe Default Typing is enabled by default NOTE: but still an issue when Default Typing is enabled. + NOTE: https://github.com/FasterXML/jackson-databind/commit/3e8fa3beea49ea62109df9e643c9cb678dabdde1 CVE-2020-36186 (FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interact ...) - - jackson-databind + - jackson-databind 2.12.1-1 [buster] - jackson-databind (Minor issue) [stretch] - jackson-databind (Minor issue) NOTE: https://github.com/FasterXML/jackson-databind/issues/2997 NOTE: Starting from 2.10 series mitigated as Safe Default Typing is enabled by default NOTE: but still an issue when Default Typing is enabled. + NOTE: https://github.com/FasterXML/jackson-databind/commit/3e8fa3beea49ea62109df9e643c9cb678dabdde1 CVE-2020-36185 (FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interact ...) - jackson-databind [buster] - jackson-databind (Minor issue) -- cgit v1.2.3