{"id":"CVE-2020-11112","details":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).","aliases":["GHSA-58pp-9c76-5625"],"modified":"2026-04-16T00:04:41.506414231Z","published":"2020-03-31T05:15:13.070Z","related":["CGA-qjg8-rgg4-rq49"],"references":[{"type":"WEB","url":"https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062"},{"type":"ADVISORY","url":"https://github.com/FasterXML/jackson-databind/issues/2666"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20200403-0002/"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujan2021.html"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"FIX","url":"https://github.com/FasterXML/jackson-databind/issues/2666"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fasterxml/jackson-databind","events":[{"introduced":"e969f0a31b781f5dfb74e16ddd5ee4b4fa36e8d8"},{"fixed":"1d919062ec351a925a628be2986224383c27f561"}]}],"versions":["jackson-databind-2.6.7.1","jackson-databind-2.7.9.2","jackson-databind-2.7.9.3","jackson-databind-2.7.9.4","jackson-databind-2.7.9.5","jackson-databind-2.7.9.6","jackson-databind-2.7.9.7","jackson-databind-2.8.10","jackson-databind-2.8.11","jackson-databind-2.8.11.1","jackson-databind-2.8.11.2","jackson-databind-2.8.11.3","jackson-databind-2.8.11.4","jackson-databind-2.8.11.5","jackson-databind-2.8.11.6","jackson-databind-2.9.0","jackson-databind-2.9.1","jackson-databind-2.9.10","jackson-databind-2.9.10.1","jackson-databind-2.9.10.2","jackson-databind-2.9.10.3","jackson-databind-2.9.2","jackson-databind-2.9.3","jackson-databind-2.9.4","jackson-databind-2.9.5","jackson-databind-2.9.6","jackson-databind-2.9.7","jackson-databind-2.9.8","jackson-databind-2.9.9","jackson-databind-2.9.9.1","jackson-databind-2.9.9.2","jackson-databind-2.9.9.3"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-11112.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}