CVE-2020-24750
Publication date 17 September 2020
Last updated 11 July 2025
Ubuntu priority
Cvss 3 Severity Score
Description
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| jackson-databind | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial | Ignored end of standard support, was needs-triage | |
| 14.04 LTS trusty |
Needs evaluation
|
Notes
sbeattie
according to debian, mitigated in 2.10 series (focal) and newer as Safe Default Typing is enabled by default but still an issue when Default Typing is enabled.
Severity score breakdown
CVSS version: CVSS v3.0
Base score
8.1 · High
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H