Loading
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Use CWE-502, Fasterxml vendor hub and Jackson-Databind product page to widen CVE-2021-20190 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-10650, CVE-2020-36183 and CVE-2020-36182 for nearby disclosures in the same product family.