A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
2020-03-02T17:15:17.813
2024-11-21T04:27:37.527
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fasterxml | jackson-databind | < 2.6.7.3 | Yes |
Application | fasterxml | jackson-databind | < 2.8.11.5 | Yes |
Application | fasterxml | jackson-databind | < 2.9.10 | Yes |
Application | redhat | decision_manager | 7.0 | Yes |
Application | redhat | jboss_data_grid | - | Yes |
Application | redhat | jboss_data_grid | 7.0.0 | Yes |
Application | redhat | jboss_enterprise_application_platform | 7.0 | Yes |
Application | redhat | jboss_fuse | 7.0.0 | Yes |
Application | redhat | openshift_container_platform | 4.3 | Yes |
Application | redhat | process_automation | 7.0 | Yes |
Application | apache | geode | 1.12.0 | Yes |