CVE-2019-20330
medium
CVSS v3
—
CVSS v2
—
VIR risk
5.5
Description
Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2020-1644.html
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2020:1644
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2019-20330
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2019-20330.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bookworm | fixed | 2.10.1-1 |
| debian | bullseye | fixed | 2.10.1-1 |
| debian | forky | fixed | 2.10.1-1 |
| debian | sid | fixed | 2.10.1-1 |
| debian | trixie | fixed | 2.10.1-1 |
| rocky | 8 | fixed | |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | com.fasterxml.jackson.core:jackson-databind | >=2.0.0,<2.6.7.4 | 2.6.7.4 |
| Maven | com.fasterxml.jackson.core:jackson-databind | >=2.7.0,<2.7.9.7 | 2.7.9.7 |
| Maven | com.fasterxml.jackson.core:jackson-databind | >=2.8.0,<2.8.11.5 | 2.8.11.5 |
| Maven | com.fasterxml.jackson.core:jackson-databind | >=2.9.0,<2.9.10.2 | 2.9.10.2 |
References
- https://www.suse.com/security/cve/CVE-2019-20330.html
- https://nvd.nist.gov/vuln/detail/CVE-2019-20330
- https://github.com/FasterXML/jackson-databind/issues/2526
- https://github.com/FasterXML/jackson-databind/commit/eb254813cc822d0af015ce8fe05febf50721dc53
- https://github.com/FasterXML/jackson-databind/commit/fc4214a883dc087070f25da738ef0d49c2f3387e
- https://lists.apache.org/thread.html/r909c822409a276ba04dc2ae31179b16f6864ba02c4f9911bdffebf95@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/ra2e572f568de8df5ba151e6aebb225a0629faaf0476bf7c7ed877af8@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/ra5ce96faec37c26b0aa15b4b6a8b1cbb145a748653e56ae83e9685d0@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/ra8a80dbc7319916946397823aec0d893d24713cbf7b5aee0e957298c@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rb532fed78d031fff477fd840b81946f6d1200f93a63698dae65aa528@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/rd1f346227e11fc515914f3a7b20d81543e51e5822ba71baa0452634a@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rd49cfa41bbb71ef33b53736a6af2aa8ba88c2106e30f2a34902a87d2@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rd6c6fef14944f3dcfb58d35f9317eb1c32a700e86c1b5231e45d3d0b@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E
- https://lists.apache.org/thread.html/rfa57d9c2a27d3af14c69607fb1a3da00e758b2092aa88eb6a51b6e99@%3Cissues.zookeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html
- https://security.netapp.com/advisory/ntap-20200127-0004
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://github.com/FasterXML/jackson-databind
- https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.10.1...jackson-databind-2.9.10.2
- https://lists.apache.org/thread.html/r107c8737db39ec9ec4f4e7147b249e29be79170b9ef4b80528105a2d@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E
Verify integrity in audit chain (admin only). AS-IS.