Adam Cameron
https://i2.paste.pics/f08e330be91f100167fd18306e70f89c.png▾
zackster
06/06/2023, 9:28 AMAdam Cameron
https://i2.paste.pics/fdec1a36562a785b2721b6a372af837e.png▾
zackster
06/06/2023, 9:29 AMzackster
06/06/2023, 9:29 AMAdam Cameron
Adam Cameron
Mark Drew (he/him)
06/06/2023, 9:31 AMAdam Cameron
Adam Cameron
Mark Drew (he/him)
06/06/2023, 9:31 AMzackster
06/06/2023, 9:31 AMMark Drew (he/him)
06/06/2023, 9:32 AMzackster
06/06/2023, 9:33 AMzackster
06/06/2023, 9:34 AMAdam Cameron
zackster
06/06/2023, 9:37 AMzackster
06/06/2023, 9:37 AMMark Drew (he/him)
06/06/2023, 9:38 AMAdam Cameron
Severity & Vulnerability Package Version Fixed in
C 10 Server-Side Request Forgery (SSRF) CVE-2018-14721 jackson-databind 2.9.6 2.9.7
C 9.8 Integer Overflow or Wraparound CVE-2022-41903 git 1:2.30.2-1 1:2.30.2-1+deb11u1
C 9.8 Deserialization of Untrusted Data CVE-2019-14892 jackson-databind 2.9.6 2.9.10
C 9.8 Integer Overflow or Wraparound CVE-2022-3515 libksba 1.5.0-3 1.5.0-3+deb11u1
C 9.8 Deserialization of Untrusted Data CVE-2019-16942 jackson-databind 2.9.6 2.9.10.1
C 9.8 Integer Overflow or Wraparound CVE-2022-23521 git 1:2.30.2-1 1:2.30.2-1+deb11u1
C 9.8 Deserialization of Untrusted Data CVE-2018-14720 jackson-databind 2.9.6 2.9.7
C 9.8 Deserialization of Untrusted Data CVE-2018-19361 jackson-databind 2.9.6 2.9.8
C 9.8 Deserialization of Untrusted Data CVE-2020-9548 jackson-databind 2.9.6 2.9.10.4
C 9.8 Exposure of Sensitive Information to an Unauthorized Actor CVE-2022-32221 curl 7.74.0-1.3+deb11u2 7.74.0-1.3+deb11u5
C 9.8 Deserialization of Untrusted Data CVE-2019-17267 jackson-databind 2.9.6 2.9.10
C 9.8 Deserialization of Untrusted Data CVE-2019-14893 jackson-databind 2.9.6 2.9.10
C 9.8 Deserialization of Untrusted Data CVE-2019-20330 jackson-databind 2.9.6 2.9.10.2
C 9.8 Deserialization of Untrusted Data CVE-2018-19362 jackson-databind 2.9.6 2.9.8
C 9.8 Deserialization of Untrusted Data CVE-2020-8840 jackson-databind 2.9.6 2.9.10.3
C 9.8 Out-of-bounds Write CVE-2022-37434 zlib 1:1.2.11.dfsg-2+deb11u1 1:1.2.11.dfsg-2+deb11u2
C 9.8 Deserialization of Untrusted Data CVE-2019-14540 jackson-databind 2.9.6 2.9.10
C 9.8 Deserialization of Untrusted Data CVE-2019-17531 jackson-databind 2.9.6 2.9.10.1
C 9.8 Deserialization of Untrusted Data CVE-2020-9546 jackson-databind 2.9.6 2.9.10.4
C 9.8 Deserialization of Untrusted Data CVE-2020-9547 jackson-databind 2.9.6 2.9.10.4
C 9.8 Deserialization of Untrusted Data CVE-2018-14719 jackson-databind 2.9.6 2.9.7
C 9.8 Deserialization of Untrusted Data CVE-2018-19360 jackson-databind 2.9.6 2.9.8
C 9.8 Deserialization of Untrusted Data CVE-2015-7501 commons-collections 3.2.1 3.2.2
C 9.8 Integer Overflow or Wraparound CVE-2022-47629 libksba 1.5.0-3 1.5.0-3+deb11u2
C 9.8 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') CVE-2019-14379 jackson-databind 2.9.6 2.9.9.2
C 9.8 Deserialization of Untrusted Data CVE-2019-16943 jackson-databind 2.9.6 2.9.10.1
C 9.8 Deserialization of Untrusted Data CVE-2018-14718 jackson-databind 2.9.6 2.9.7
C 9.8 Deserialization of Untrusted Data CVE-2019-16335 jackson-databind 2.9.6 2.9.10
C 9.1 Out-of-bounds Read CVE-2022-1586 pcre2 10.36-2 10.36-2+deb11u1
C 9.1 Out-of-bounds Read CVE-2022-1587 pcre2 10.36-2 10.36-2+deb11u1Adam Cameron
zackster
06/06/2023, 9:40 AM