Back to Vulnerability Directory
HIGHFixed upstream

CVE-2021-20190

flaw was found in jackson-databind before 2.9.10.7.

Technology

Apache NiFi

CVSS Score

8.1 / 10.0

Affected Versions

>=1.7.0 <=1.12.1

Upstream Fix

See upstream advisory

Published

January 19, 2021

OSSeva Coverage

Fixed upstream

Description

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Is your Apache NiFi deployment affected?

If you're running >=1.7.0 <=1.12.1, you need this patch. Book a discovery call to get covered.