CVE-2020-10650
published 2022-12-26CVE-2020-10650: A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or…
PriorityP278high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
3.33%
87.3th percentile
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jackson-databind | < jackson-databind 2.11.1-1 (bookworm) | jackson-databind 2.11.1-1 (bookworm) |
| fasterxml | jackson-databind | < 2.9.10.4 | 2.9.10.4 |
| fasterxml | jackson-databind | — | — |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| oracle | retail_merchandising_system | — | — |
| oracle | retail_sales_audit | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect deserialization gadget chain abuse via ignite-jta class org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup in Jackson-databind polymorphic type handling ↗
- →Detect deserialization gadget chain abuse via ignite-jta class org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory in Jackson-databind polymorphic type handling ↗
- →Detect deserialization gadget chain abuse via quartz-core class org.quartz.utils.JNDIConnectionProvider in Jackson-databind polymorphic type handling ↗
- ·Vulnerability affects jackson-databind through version 2.9.10.4; versions fixed at 2.11.1-1 (Debian) are not affected. Ensure version scope is confirmed before applying detections. ↗
- ·Exploitation requires that polymorphic type handling (default typing) is enabled in the Jackson-databind configuration AND the vulnerable gadget classes (ignite-jta or quartz-core) are present on the classpath. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vulncheck8.1HIGH
vendor_debian8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2020-10650: A deserialization flaw was discovered in jackson-databind through 2
osv·2022-12-26·CVSS 8.1
CVE-2020-10650 [HIGH] CVE-2020-10650: A deserialization flaw was discovered in jackson-databind through 2
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.
OSV
jackson-databind vulnerable to unsafe deserialization
osv·2022-07-15
CVE-2020-10650 [HIGH] jackson-databind vulnerable to unsafe deserialization
jackson-databind vulnerable to unsafe deserialization
The com.fasterxml.jackson.core:jackson-databind library before version 2.9.10.4 is vulnerable to an Unsafe Deserialization vulnerability when handling interactions related to the class `ignite-jta`.
GHSA
jackson-databind vulnerable to unsafe deserialization
ghsa·2022-07-15
CVE-2020-10650 [HIGH] CWE-502 jackson-databind vulnerable to unsafe deserialization
jackson-databind vulnerable to unsafe deserialization
The com.fasterxml.jackson.core:jackson-databind library before version 2.9.10.4 is vulnerable to an Unsafe Deserialization vulnerability when handling interactions related to the class `ignite-jta`.
VulnCheck
debian debian_linux Deserialization of Untrusted Data
vulncheck·2020·CVSS 8.1
CVE-2020-10650 [HIGH] debian debian_linux Deserialization of Untrusted Data
debian debian_linux Deserialization of Untrusted Data
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.
Affected: debian debian_linux
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.cloudsek.com/blog/androxgh0st-continues-exploitation-operators-compromise-a-us-university-for-hosting-c2-logger
Debian
CVE-2020-10650: jackson-databind - A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It c...
vendor_debian·2020·CVSS 8.1
CVE-2020-10650 [HIGH] CVE-2020-10650: jackson-databind - A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It c...
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.
Scope: local
bookworm: resolved (fixed in 2.11.1-1)
bullseye: resolved (fixed in 2.11.1-1)
forky: resolved (fixed in 2.11.1-1)
sid: resolved (fixed in 2.11.1-1)
trixie: resolved (fixed in 2.11.1-1)
No detection rules found.
No public exploits indexed.
https://github.com/FasterXML/jackson-databind/commit/a424c038ba0c0d65e579e22001dec925902ac0efhttps://github.com/FasterXML/jackson-databind/issues/2658https://github.com/advisories/GHSA-rpr3-cw39-3pxhhttps://lists.debian.org/debian-lts-announce/2023/04/msg00032.htmlhttps://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062https://security.netapp.com/advisory/ntap-20230818-0007/https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2022.htmlhttps://github.com/FasterXML/jackson-databind/commit/a424c038ba0c0d65e579e22001dec925902ac0efhttps://github.com/FasterXML/jackson-databind/issues/2658https://github.com/advisories/GHSA-rpr3-cw39-3pxhhttps://lists.debian.org/debian-lts-announce/2023/04/msg00032.htmlhttps://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062https://security.netapp.com/advisory/ntap-20230818-0007/https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2022.html
2022-12-26
Published
Exploited in the wild