CVE-2020-24616
published 2020-08-25CVE-2020-24616: FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to…
PriorityP348high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
9.42%
94.9th percentile
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jackson-databind | < jackson-databind 2.12.1-1 (bookworm) | jackson-databind 2.12.1-1 (bookworm) |
| fasterxml | jackson-databind | >= 0 < 2.12.1-1 | 2.12.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.12.1-1 | 2.12.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.12.1-1 | 2.12.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.12.1-1 | 2.12.1-1 |
| fasterxml | jackson-databind | >= 2.0.0 < 2.9.10.6 | 2.9.10.6 |
| oracle | agile_plm | — | — |
| oracle | application_testing_suite | — | — |
| oracle | autovue_for_agile_product_lifecycle_management | — | — |
| oracle | banking_liquidity_management | — | — |
| oracle | banking_liquidity_management | — | — |
| oracle | banking_liquidity_management | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | blockchain_platform | < 21.1.2 | 21.1.2 |
| oracle | communications_calendar_server | — | — |
| oracle | communications_calendar_server | — | — |
| oracle | communications_cloud_native_core_unified_data_repository | — | — |
| oracle | communications_contacts_server | — | — |
| oracle | communications_contacts_server | — | — |
| oracle | communications_diameter_signaling_router | 8.0.0 – 8.2.2 | — |
| oracle | communications_element_manager | 8.2.0 – 8.2.4.0 | — |
| oracle | communications_evolved_communications_application_server | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Code Injection in jackson-databind
ghsa·2021-12-09
CVE-2020-24616 [HIGH] CWE-502 Code Injection in jackson-databind
Code Injection in jackson-databind
This project contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
OSV
Code Injection in jackson-databind
osv·2021-12-09
CVE-2020-24616 [HIGH] Code Injection in jackson-databind
Code Injection in jackson-databind
This project contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
OSV
CVE-2020-24616: FasterXML jackson-databind 2
osv·2020-08-25·CVSS 8.1
CVE-2020-24616 [HIGH] CVE-2020-24616: FasterXML jackson-databind 2
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
Red Hat
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource
vendor_redhat·2020-08-25·CVSS 8.1
CVE-2020-24616 [HIGH] CWE-96 jackson-databind: mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource
jackson-databind: mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
A flaw was found in FasterXML jackson-databind 2.x in versions prior to 2.9.10.6. The interaction between serialization gadgets and typing are mishandled. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: The Red Hat JBoss Enterprise Application Platform 7 does ship the vulnerable component but has a mandatory whitelist which blocks all wicked serializing classes and does not enable the u
Debian
CVE-2020-24616: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee...
vendor_debian·2020·CVSS 8.1
CVE-2020-24616 [HIGH] CVE-2020-24616: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee...
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
Scope: local
bookworm: resolved (fixed in 2.12.1-1)
bullseye: resolved (fixed in 2.12.1-1)
forky: resolved (fixed in 2.12.1-1)
sid: resolved (fixed in 2.12.1-1)
trixie: resolved (fixed in 2.12.1-1)
No detection rules found.
No public exploits indexed.
arXiv
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
arxiv_fulltext·2026-03
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
## Abstract
Open-source software supply chain security relies heavily on assessing affected versions of library vulnerabilities. While prior studies have leveraged exploits for verifying vulnerability affected versions, they point out a key limitation that exploits are version-specific and cannot be directly applied across library versions. Despite being widely acknowledged, this limitation has not been systematically validated at scale, leaving the actual applicability of exploits across versions unexplored. To fill this gap, we conduct the first large-scale empirical study on exploit applicability across library versions. We construct a comprehensive dataset consisting of 259 exploits spanning 128 Java libraries and 28,150 historical versions, covering 61 CWEs that account for 76.33% of
Bugzilla
CVE-2020-24616 jackson-databind: mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource
bugzilla·2020-08-26·CVSS 8.1
CVE-2020-24616 [HIGH] CVE-2020-24616 jackson-databind: mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource
CVE-2020-24616 jackson-databind: mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
Discussion:
This vulnerability is out of security support scope for the following products:
* Red Hat Enterprise Application Platform 6
* Red Hat JBoss BPMS 6
* Red Hat JBoss BRMS 6
* Red Hat JBoss Data Virtualization 6
* Red Hat Data Grid 6
* Red Hat JBoss Fuse 6
* Red Hat JBoss AMQ 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
---
Mitigation:
The following conditions are needed for an exploit,
https://github.com/FasterXML/jackson-databind/issues/2814https://lists.debian.org/debian-lts-announce/2021/04/msg00025.htmlhttps://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062https://security.netapp.com/advisory/ntap-20200904-0006/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://github.com/FasterXML/jackson-databind/issues/2814https://lists.debian.org/debian-lts-announce/2021/04/msg00025.htmlhttps://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062https://security.netapp.com/advisory/ntap-20200904-0006/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-08-25
Published