CVE-2020-11113
published 2020-03-31CVE-2020-11113: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to…
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
6.28%
92.8th percentile
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jackson-databind | < jackson-databind 2.11.1-1 (bookworm) | jackson-databind 2.11.1-1 (bookworm) |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.4.2-3ubuntu0.1~esm2 | 2.4.2-3ubuntu0.1~esm2 |
| fasterxml | jackson-databind | >= 2.0.0 < 2.9.10.4 | 2.9.10.4 |
| oracle | agile_plm | — | — |
| oracle | autovue_for_agile_product_lifecycle_management | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_platform | 2.4.0 – 2.9.0 | — |
| oracle | communications_calendar_server | — | — |
| oracle | communications_contacts_server | — | — |
| oracle | communications_diameter_signaling_router | 8.0.0 – 8.2.2 | — |
| oracle | communications_element_manager | 8.2.0 – 8.2.2 | — |
| oracle | communications_evolved_communications_application_server | — | — |
| oracle | communications_instant_messaging_server | — | — |
| oracle | communications_network_charging_and_control | — | — |
| oracle | communications_network_charging_and_control | 12.0.0 – 12.0.3 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Flag deserialization payloads referencing the openjpa gadget class 'org.apache.openjpa.ee.WASRegistryManagedRuntime' in JSON input streams, which is the serialization gadget abused in this CVE. ↗
- →Exploitation requires polymorphic typing to be enabled — monitor for use of enableDefaultTyping() or @JsonTypeInfo with id.CLASS or id.MINIMAL_CLASS in application configurations, as these are prerequisites for the vulnerability to be triggered. ↗
- ·Vulnerability is only exploitable when polymorphic deserialization is enabled (enableDefaultTyping() or @JsonTypeInfo with id.CLASS/id.MINIMAL_CLASS). Deployments without these configurations are not affected. ↗
- ·Red Hat Satellite 6 does not enable polymorphic deserialization and is therefore not exploitable in its default configuration. ↗
- ·The PKI module in Red Hat Enterprise Linux 8 does not enable polymorphic deserialization in its default configuration, lowering exploitability. ↗
- ·Fedora 30+ ships jackson-databind 2.10.0+, which is not affected; only versions in the 2.x before 2.9.10.4 range are vulnerable. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Jackson Databind vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 9.8
CVE-2019-14540 [CRITICAL] Jackson Databind vulnerabilities
Title: Jackson Databind vulnerabilities
Summary: Several security issues were fixed in Jackson Databind.
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to execute
arbitrary code or other unspecified impact. (CVE-2018-12022,
CVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,
CVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,
CVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,
CVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,
CVE-2020-10672, CVE-2020-10673, CVE-2020-109
Red Hat
jackson-databind: Serialization gadgets in org.apache.openjpa.ee.WASRegistryManagedRuntime
vendor_redhat·2020-03-28·CVSS 8.8
CVE-2020-11113 [HIGH] CWE-96 jackson-databind: Serialization gadgets in org.apache.openjpa.ee.WASRegistryManagedRuntime
jackson-databind: Serialization gadgets in org.apache.openjpa.ee.WASRegistryManagedRuntime
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
A flaw was found in jackson-databind 2.x in versions prior to 2.9.10.4. The interaction between serialization gadgets and typing is mishandled. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: Red Hat Satellite 6 does not enable polymorphic deserialization which is a required configuration for the vulnerability to be used. We may update the jackson-databind dependency in a future release.
Red Hat OpenStack Platform ships OpenDaylight,
Debian
CVE-2020-11113: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
vendor_debian·2020·CVSS 8.8
CVE-2020-11113 [HIGH] CVE-2020-11113: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
Scope: local
bookworm: resolved (fixed in 2.11.1-1)
bullseye: resolved (fixed in 2.11.1-1)
forky: resolved (fixed in 2.11.1-1)
sid: resolved (fixed in 2.11.1-1)
trixie: resolved (fixed in 2.11.1-1)
OSV
jackson-databind vulnerabilities
osv·2021-03-15·CVSS 9.8
CVE-2018-11307 [CRITICAL] jackson-databind vulnerabilities
jackson-databind vulnerabilities
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to execute
arbitrary code or other unspecified impact. (CVE-2018-12022,
CVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,
CVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,
CVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,
CVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,
CVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,
CVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2
OSV
jackson-databind mishandles the interaction between serialization gadgets and typing
osv·2020-05-15
CVE-2020-11113 [HIGH] jackson-databind mishandles the interaction between serialization gadgets and typing
jackson-databind mishandles the interaction between serialization gadgets and typing
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
GHSA
jackson-databind mishandles the interaction between serialization gadgets and typing
ghsa·2020-05-15
CVE-2020-11113 [HIGH] CWE-502 jackson-databind mishandles the interaction between serialization gadgets and typing
jackson-databind mishandles the interaction between serialization gadgets and typing
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
OSV
CVE-2020-11113: FasterXML jackson-databind 2
osv·2020-03-31·CVSS 8.8
CVE-2020-11113 [HIGH] CVE-2020-11113: FasterXML jackson-databind 2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-11113 jackson-databind: Serialization gadgets in org.apache.openjpa.ee.WASRegistryManagedRuntime
bugzilla·2020-04-06·CVSS 8.8
CVE-2020-11113 [HIGH] CVE-2020-11113 jackson-databind: Serialization gadgets in org.apache.openjpa.ee.WASRegistryManagedRuntime
CVE-2020-11113 jackson-databind: Serialization gadgets in org.apache.openjpa.ee.WASRegistryManagedRuntime
A vulnerability was found in Jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
Discussion:
External References:
https://github.com/FasterXML/jackson-databind/issues/2670
---
Created jackson-databind tracking bugs for this issue:
Affects: fedora-all [bug 1821316]
---
Upstream fix:
https://github.com/FasterXML/jackson-databind/commit/e2ba12d5d60715d95105e3e790fc234cfb59893d
---
Mitigation:
The following conditions are needed for an exploit, we recommend avoiding all if possible
* Deserialization from sources you do not control
* `enableDefaultTypin
Bugzilla
CVE-2020-11113 jackson-databind: jackson-databind: mishandles the interaction between serialization gadgets and typing related to org.apache.openjpa.ee.WASRegistryManagedRuntime which could result in
bugzilla·2020-04-06·CVSS 8.8
CVE-2020-11113 [HIGH] CVE-2020-11113 jackson-databind: jackson-databind: mishandles the interaction between serialization gadgets and typing related to org.apache.openjpa.ee.WASRegistryManagedRuntime which could result in
CVE-2020-11113 jackson-databind: jackson-databind: mishandles the interaction between serialization gadgets and typing related to org.apache.openjpa.ee.WASRegistryManagedRuntime which could result in remote command execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level
Tenable
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
blogs_tenable·2022-10-19
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://github.com/FasterXML/jackson-databind/issues/2670https://lists.debian.org/debian-lts-announce/2020/04/msg00012.htmlhttps://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062https://security.netapp.com/advisory/ntap-20200403-0002/https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://github.com/FasterXML/jackson-databind/issues/2670https://lists.debian.org/debian-lts-announce/2020/04/msg00012.htmlhttps://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062https://security.netapp.com/advisory/ntap-20200403-0002/https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-03-31
Published