Skip to content

Block one more gadget type (javax.swing, CVE-2020-20190)Β #2854

@cowtowncoder

Description

@cowtowncoder

Another gadget type(s) has been reported regarding a class(es) of JDK Swing.

See https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 for description of the general problem.

Mitre id: CVE-2021-20190 (see https://nvd.nist.gov/vuln/detail/CVE-2021-20190)
Reporter(s): Yangkun(ICSL)

Fix is be included in:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions