2020-01-03 04:01:03 +00:00
{
2020-04-16 19:01:28 +00:00
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org" ,
"ID" : "CVE-2019-20330" ,
"STATE" : "PUBLIC"
2020-01-03 04:01:03 +00:00
} ,
2020-04-16 19:01:28 +00:00
"affects" : {
"vendor" : {
"vendor_data" : [
2020-01-03 04:01:03 +00:00
{
2020-04-16 19:01:28 +00:00
"product" : {
"product_data" : [
2020-01-03 04:01:03 +00:00
{
2020-04-16 19:01:28 +00:00
"product_name" : "n/a" ,
"version" : {
"version_data" : [
2020-01-03 04:01:03 +00:00
{
2020-04-16 19:01:28 +00:00
"version_value" : "n/a"
2020-01-03 04:01:03 +00:00
}
]
}
}
]
} ,
2020-04-16 19:01:28 +00:00
"vendor_name" : "n/a"
2020-01-03 04:01:03 +00:00
}
]
}
} ,
2020-04-16 19:01:28 +00:00
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
"value" : "FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking."
2020-01-03 04:01:03 +00:00
}
]
} ,
2020-04-16 19:01:28 +00:00
"problemtype" : {
"problemtype_data" : [
2020-01-03 04:01:03 +00:00
{
2020-04-16 19:01:28 +00:00
"description" : [
2020-01-03 04:01:03 +00:00
{
2020-04-16 19:01:28 +00:00
"lang" : "eng" ,
"value" : "n/a"
2020-01-03 04:01:03 +00:00
}
]
}
]
} ,
2020-04-16 19:01:28 +00:00
"references" : {
"reference_data" : [
2020-01-15 05:01:09 +00:00
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[druid-commits] 20200114 [GitHub] [druid] ccaominh opened a new pull request #9189: Suppress CVE-2019-20330 for htrace-core-4.0.1" ,
"url" : "https://lists.apache.org/thread.html/rd6c6fef14944f3dcfb58d35f9317eb1c32a700e86c1b5231e45d3d0b@%3Ccommits.druid.apache.org%3E"
2020-01-15 07:01:16 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[druid-commits] 20200115 [GitHub] [druid] clintropolis merged pull request #9189: Suppress CVE-2019-20330 for htrace-core-4.0.1" ,
"url" : "https://lists.apache.org/thread.html/rb532fed78d031fff477fd840b81946f6d1200f93a63698dae65aa528@%3Ccommits.druid.apache.org%3E"
2020-01-15 07:01:16 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[druid-commits] 20200115 [GitHub] [druid] ccaominh opened a new pull request #9191: [Backport] Suppress CVE-2019-20330 for htrace-core-4.0.1 (#9189)" ,
"url" : "https://lists.apache.org/thread.html/r5c3644c97f0434d1ceb48ff48897a67bdbf3baf7efbe7d04625425b3@%3Ccommits.druid.apache.org%3E"
2020-01-15 11:01:07 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[druid-commits] 20200115 [GitHub] [druid] clintropolis merged pull request #9191: [Backport] Suppress CVE-2019-20330 for htrace-core-4.0.1 (#9189)" ,
"url" : "https://lists.apache.org/thread.html/r7fb123e7dad49af5886cfec7135c0fd5b74e4c67af029e1dc91ba744@%3Ccommits.druid.apache.org%3E"
2020-01-15 11:01:07 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[druid-commits] 20200115 [druid] branch 0.17.0 updated: Suppress CVE-2019-20330 for htrace-core-4.0.1 (#9189) (#9191)" ,
"url" : "https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E"
2020-01-18 21:01:08 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-dev] 20200118 Build failed in Jenkins: zookeeper-master-maven-owasp #329" ,
"url" : "https://lists.apache.org/thread.html/r107c8737db39ec9ec4f4e7147b249e29be79170b9ef4b80528105a2d@%3Cdev.zookeeper.apache.org%3E"
2020-01-18 21:01:08 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-dev] 20200118 [jira] [Created] (ZOOKEEPER-3699) upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/r5c14fdcabdeaba258857bcb67198652e4dce1d33ddc590cd81d82393@%3Cdev.zookeeper.apache.org%3E"
2020-01-18 21:01:08 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-issues] 20200118 [jira] [Created] (ZOOKEEPER-3699) upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/r909c822409a276ba04dc2ae31179b16f6864ba02c4f9911bdffebf95@%3Cissues.zookeeper.apache.org%3E"
2020-01-19 00:01:05 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-issues] 20200118 [jira] [Commented] (ZOOKEEPER-3699) upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/r5d3d10fdf28110da3f9ac1b7d08d7e252f98d7d37ce0a6bd139a2e4f@%3Cissues.zookeeper.apache.org%3E"
2020-01-22 19:01:16 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-issues] 20200122 [jira] [Commented] (ZOOKEEPER-3699) upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/r50f513772f12e1babf65c7c2b9c16425bac2d945351879e2e267517f@%3Cissues.zookeeper.apache.org%3E"
2020-01-22 19:01:16 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-dev] 20200122 Re: 3.5.7" ,
"url" : "https://lists.apache.org/thread.html/ra8a80dbc7319916946397823aec0d893d24713cbf7b5aee0e957298c@%3Cdev.zookeeper.apache.org%3E"
2020-01-22 19:01:16 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-issues] 20200122 [jira] [Assigned] (ZOOKEEPER-3699) upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/rfa57d9c2a27d3af14c69607fb1a3da00e758b2092aa88eb6a51b6e99@%3Cissues.zookeeper.apache.org%3E"
2020-01-22 19:01:16 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-notifications] 20200122 [GitHub] [zookeeper] phunt commented on issue #1232: ZOOKEEPER-3699: upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/ra2e572f568de8df5ba151e6aebb225a0629faaf0476bf7c7ed877af8@%3Cnotifications.zookeeper.apache.org%3E"
2020-01-22 19:01:16 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-issues] 20200122 [jira] [Updated] (ZOOKEEPER-3699) upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/r428735963bee7cb99877b88d3228e28ec28af64646455c4f3e7a3c94@%3Cissues.zookeeper.apache.org%3E"
2020-01-22 19:01:16 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-notifications] 20200122 [GitHub] [zookeeper] phunt opened a new pull request #1232: ZOOKEEPER-3699: upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/ra5ce96faec37c26b0aa15b4b6a8b1cbb145a748653e56ae83e9685d0@%3Cnotifications.zookeeper.apache.org%3E"
2020-01-23 12:01:07 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-issues] 20200123 [jira] [Commented] (ZOOKEEPER-3699) upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/rd1f346227e11fc515914f3a7b20d81543e51e5822ba71baa0452634a@%3Cissues.zookeeper.apache.org%3E"
2020-01-23 12:01:07 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-commits] 20200123 [zookeeper] branch branch-3.6 updated: ZOOKEEPER-3699: upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/r7a0821b44247a1e6c6fe5f2943b90ebc4f80a8d1fb0aa9a8b29a59a2@%3Ccommits.zookeeper.apache.org%3E"
2020-01-23 12:01:07 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-commits] 20200123 [zookeeper] branch branch-3.5 updated: ZOOKEEPER-3699: upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/r67f4d4c48197454b83d62afbed8bebbda3764e6e3a6e26a848961764@%3Ccommits.zookeeper.apache.org%3E"
2020-01-23 12:01:07 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-issues] 20200123 [jira] [Resolved] (ZOOKEEPER-3699) upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/r707d23bb9ee245f50aa909add0da6e8d8f24719b1278ddd99d2428b2@%3Cissues.zookeeper.apache.org%3E"
2020-01-23 12:01:07 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-notifications] 20200123 [GitHub] [zookeeper] asfgit closed pull request #1232: ZOOKEEPER-3699: upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/rd49cfa41bbb71ef33b53736a6af2aa8ba88c2106e30f2a34902a87d2@%3Cnotifications.zookeeper.apache.org%3E"
2020-01-23 12:01:07 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-notifications] 20200123 [GitHub] [zookeeper] nkalmar commented on issue #1232: ZOOKEEPER-3699: upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/r2c77dd6ab8344285bd8e481b57cf3029965a4b0036eefccef74cdd44@%3Cnotifications.zookeeper.apache.org%3E"
2020-01-23 12:01:07 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-issues] 20200123 [jira] [Updated] (ZOOKEEPER-3699) upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/r3f8180d0d25a7c6473ebb9714b0c1d19a73f455ae70d0c5fefc17e6c@%3Cissues.zookeeper.apache.org%3E"
2020-01-23 12:01:07 +00:00
} ,
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[zookeeper-commits] 20200123 [zookeeper] branch master updated: ZOOKEEPER-3699: upgrade jackson-databind to address CVE-2019-20330" ,
"url" : "https://lists.apache.org/thread.html/r8831b7fa5ca87a1cf23ee08d6dedb7877a964c1d2bd869af24056a63@%3Ccommits.zookeeper.apache.org%3E"
2020-01-27 11:01:12 +00:00
} ,
2020-02-20 18:01:07 +00:00
{
2020-04-16 19:01:28 +00:00
"refsource" : "MLIST" ,
"name" : "[debian-lts-announce] 20200220 [SECURITY] [DLA 2111-1] jackson-databind security update" ,
"url" : "https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html"
2020-04-14 14:04:09 -07:00
} ,
{
2020-04-16 19:01:28 +00:00
"url" : "https://www.oracle.com/security-alerts/cpuapr2020.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/security-alerts/cpuapr2020.html"
2020-07-14 13:55:31 -07:00
} ,
{
2020-07-15 03:02:07 +00:00
"url" : "https://www.oracle.com/security-alerts/cpujul2020.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/security-alerts/cpujul2020.html"
} ,
{
"url" : "https://github.com/FasterXML/jackson-databind/issues/2526" ,
"refsource" : "MISC" ,
"name" : "https://github.com/FasterXML/jackson-databind/issues/2526"
} ,
{
"url" : "https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.10.1...jackson-databind-2.9.10.2" ,
"refsource" : "MISC" ,
"name" : "https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.10.1...jackson-databind-2.9.10.2"
} ,
{
"refsource" : "CONFIRM" ,
"name" : "https://security.netapp.com/advisory/ntap-20200127-0004/" ,
"url" : "https://security.netapp.com/advisory/ntap-20200127-0004/"
2020-07-29 12:01:25 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[bookkeeper-issues] 20200729 [GitHub] [bookkeeper] padma81 opened a new issue #2387: Security vulnerabilities in the apache/bookkeeper-4.9.2 image" ,
"url" : "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E"
2020-08-31 14:01:29 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[geode-issues] 20200831 [jira] [Created] (GEODE-8471) Dependency security issues in geode-core-1.12" ,
"url" : "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E"
2020-10-20 12:39:21 -07:00
} ,
{
2020-10-20 22:03:07 +00:00
"url" : "https://www.oracle.com/security-alerts/cpuoct2020.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/security-alerts/cpuoct2020.html"
2021-07-20 14:01:27 -07:00
} ,
{
2021-07-21 15:02:04 +00:00
"url" : "https://www.oracle.com//security-alerts/cpujul2021.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com//security-alerts/cpujul2021.html"
2020-01-03 04:01:03 +00:00
}
]
}
}