Back to Vulnerability Directory
HIGHFixed upstream
CVE-2021-20190
flaw was found in jackson-databind before 2.9.10.7.
Technology
Apache NiFi
CVSS Score
8.1 / 10.0
Affected Versions
>=1.7.0 <=1.12.1
Upstream Fix
See upstream advisory
Published
January 19, 2021
OSSeva Coverage
Fixed upstream
Description
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Is your Apache NiFi deployment affected?
If you're running >=1.7.0 <=1.12.1, you need this patch. Book a discovery call to get covered.