Skip to content

[GHSA-cf6r-3wgc-h863] Polymorphic deserialization of malicious object in jackson-databind#1768

Closed
Osmankic-Adis_pfghub wants to merge 1 commit into
Osmankic-Adis_pfghub/advisory-improvement-1768from
Osmankic-Adis_pfghub-GHSA-cf6r-3wgc-h863
Closed

[GHSA-cf6r-3wgc-h863] Polymorphic deserialization of malicious object in jackson-databind#1768
Osmankic-Adis_pfghub wants to merge 1 commit into
Osmankic-Adis_pfghub/advisory-improvement-1768from
Osmankic-Adis_pfghub-GHSA-cf6r-3wgc-h863

Conversation

@Osmankic-Adis_pfghub
Copy link
Copy Markdown

Updates

  • CVSS
  • Severity

Comments
Looks like this was using the CVSS:3.0 score from CNA instead of the CVSS:3.1 score from NVD. I think we'd want to use the 3.1 score over the 3.0

@github-actions github-actions Bot changed the base branch from main to Osmankic-Adis_pfghub/advisory-improvement-1768 March 9, 2023 22:44
@ronwoch
Copy link
Copy Markdown

ronwoch commented Mar 10, 2023

Hi @Osmankic-Adis_pfghub, do you have any references to support changing the Integrity and Availability impacts from None to High?

@AdisOsmankicPFG
Copy link
Copy Markdown

Hi @ronwoch, if you view the NIST NVD entry you can see that the Integrity and Availability impacts are listed as High (https://nvd.nist.gov/vuln/detail/CVE-2019-14892).

@taladrane
Copy link
Copy Markdown
Collaborator

👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.

@taladrane taladrane closed this Apr 26, 2023
@github-actions github-actions Bot deleted the Osmankic-Adis_pfghub-GHSA-cf6r-3wgc-h863 branch April 26, 2023 00:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants