cbcvebase.
CVE-2020-10650
published 2022-12-26

CVE-2020-10650: A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or…

PriorityP278high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
3.33%
87.3th percentile
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianjackson-databind< jackson-databind 2.11.1-1 (bookworm)jackson-databind 2.11.1-1 (bookworm)
fasterxmljackson-databind< 2.9.10.42.9.10.4
fasterxmljackson-databind
fasterxmljackson-databind>= 0 < 2.11.1-12.11.1-1
fasterxmljackson-databind>= 0 < 2.11.1-12.11.1-1
fasterxmljackson-databind>= 0 < 2.11.1-12.11.1-1
fasterxmljackson-databind>= 0 < 2.11.1-12.11.1-1
oracleretail_merchandising_system
oracleretail_sales_audit

Detection & IOCsextracted from sources · hover to see the quote

  • Detect deserialization gadget chain abuse via ignite-jta class org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup in Jackson-databind polymorphic type handling
  • Detect deserialization gadget chain abuse via ignite-jta class org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory in Jackson-databind polymorphic type handling
  • Detect deserialization gadget chain abuse via quartz-core class org.quartz.utils.JNDIConnectionProvider in Jackson-databind polymorphic type handling
  • ·Vulnerability affects jackson-databind through version 2.9.10.4; versions fixed at 2.11.1-1 (Debian) are not affected. Ensure version scope is confirmed before applying detections.
  • ·Exploitation requires that polymorphic type handling (default typing) is enabled in the Jackson-databind configuration AND the vulnerable gadget classes (ignite-jta or quartz-core) are present on the classpath.

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vulncheck8.1HIGH
vendor_debian8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.