Skip to content

Block one more gadget type (javax.swing, CVE-2020-10969) #2642

@cowtowncoder

Description

@cowtowncoder

Another gadget type reported regarding a class in javax.swing package..
See https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 for description of the general problem.

Mitre id: CVE-2020-10969
Reporters: threedr3am

Fix will be included in:

  • 2.9.10.4
  • 2.8.11.6 (jackson-bom version 2.8.11.20200310)
  • 2.7.9.7
  • Does not affect 2.10.0 and later

Metadata

Metadata

Assignees

No one assigned

    Labels

    CVEIssues related to public CVEs (security vuln reports)

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions