NVD disclosure day

Published threat advisories for March 2, 2020

CVE advisoryCRITICAL

CVE-2020-9548

Jackson-databind Serialization Gadget Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the FasterXML jackson-databind library allows for remote code execution through mishandled serialization. This could lead to unauthorized access and control of affected systems by processing specially crafted data. Confirming its presence and reachability is crucial for assessing risk.

CVE advisoryCRITICAL

CVE-2020-9546

FasterXML Jackson Databind Serialization Gadget Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The FasterXML jackson-databind library has a vulnerability in how it handles serialization gadgets and typing, specifically related to HikariConfig. This could allow attackers to process data in unintended ways if they can reach a vulnerable application, potentially impacting system data and service behavior. The libra