-
Type:
Bug
-
Status: Closed
-
Priority:
Minor
-
Resolution: Fixed
-
Affects Version/s: 7.0 DE (7.0.10), 7.2 DXP (7.2.10), 7.3 DXP (7.3.10)
-
Component/s: REST infrastructure (vulcan), Security Vulnerability
-
CVE IDs:CVE-2020-25649
-
7.0 Fix Pack Version:100
-
7.2 Fix Pack Version:11
-
7.3 Fix Pack Version:1
Liferay DXP is bundled with Jackson Databind 2.10.3 which has known vulnerabilities. For more details, please see https://nvd.nist.gov/vuln/search/results?adv_search=true&query=cpe%3A2.3%3Aa%3Afasterxml%3Ajackson-databind%3A2.10.3%3A*%3A*%3A*%3A*%3A*%3A*%3A*