Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Block one more gadget type (caucho-quercus, CVE-2020-10673) #2660

Closed
cowtowncoder opened this issue Mar 18, 2020 · 1 comment
Closed

Block one more gadget type (caucho-quercus, CVE-2020-10673) #2660

cowtowncoder opened this issue Mar 18, 2020 · 1 comment
Labels
CVE Issues related to public CVEs (security vuln reports)
Milestone

Comments

@cowtowncoder
Copy link
Member

cowtowncoder commented Mar 18, 2020

Another gadget type(s) reported regarding a class of caucho-quercus library.
See https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 for description of the general problem.

Mitre id: CVE-2020-10673
Reporter: threedr3am'follower

Fix is included in:

@cowtowncoder cowtowncoder added 2.9 CVE Issues related to public CVEs (security vuln reports) labels Mar 18, 2020
@cowtowncoder cowtowncoder added this to the 2.9.10.4 milestone Mar 18, 2020
@cowtowncoder cowtowncoder changed the title Block one more gadget type (TO BE FILLED) Block one more gadget type (caucho-quercus, CVE-2020-10673) Mar 18, 2020
martokarski pushed a commit to atlassian/jackson-1 that referenced this issue May 8, 2020
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
CVE Issues related to public CVEs (security vuln reports)
Projects
None yet
Development

No branches or pull requests

1 participant