CVE-2020-8840Critical· 9.8▾ AbyssalPoC availableFasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 5.3 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
27%
6 GitHub repos (last check)
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
jackson-databind >= 2.0.0, < 2.7.9.7jackson-databind >= 2.8.0, < 2.8.11.5jackson-databind >= 2.9.0, < 2.9.10.3debian_linux = 8.0oncommand_api_servicesoncommand_workflow_automationservice_level_managersteelstore_cloud_integrated_storageoceanstor_9000_firmware = v300r006c20oceanstor_9000_firmware = v300r006c20spc100oceanstor_9000_firmware = v300r006c20spc200oceanstor_9000_firmware = v300r006c20spc300global_lifecycle_management_opatch < 11.2.0.3.23global_lifecycle_management_opatch >= 12.2.0.1.0, < 12.2.0.1.19global_lifecycle_management_opatch >= 13.9.4.0.0, < 13.9.4.2.1Upgrade past the affected range:
jackson-databind 2.9.10.3global_lifecycle_management_opatch 13.9.4.2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2019-14893Critical· 9.8A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic ty…
CVE-2019-14892Critical· 9.8A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes
CVE-2019-20330Critical· 9.8FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CVE-2019-14540Critical· 9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10
CVE-2019-12086High· 7.5A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9
CVE-2019-12384Medium· 5.9FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization