CVE-2020-24750
published 2020-09-17CVE-2020-24750: FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to…
PriorityP347high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
7.33%
93.7th percentile
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jackson-databind | < jackson-databind 2.12.1-1 (bookworm) | jackson-databind 2.12.1-1 (bookworm) |
| fasterxml | jackson-databind | >= 0 < 2.12.1-1 | 2.12.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.12.1-1 | 2.12.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.12.1-1 | 2.12.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.12.1-1 | 2.12.1-1 |
| fasterxml | jackson-databind | >= 2.0.0 < 2.6.7.5 | 2.6.7.5 |
| fasterxml | jackson-databind | >= 2.7.0 < 2.9.10.6 | 2.9.10.6 |
| oracle | agile_plm | — | — |
| oracle | application_testing_suite | — | — |
| oracle | autovue_for_agile_product_lifecycle_management | — | — |
| oracle | banking_corporate_lending_process_management | — | — |
| oracle | banking_corporate_lending_process_management | — | — |
| oracle | banking_corporate_lending_process_management | — | — |
| oracle | banking_credit_facilities_process_management | — | — |
| oracle | banking_credit_facilities_process_management | — | — |
| oracle | banking_credit_facilities_process_management | — | — |
| oracle | banking_liquidity_management | — | — |
| oracle | banking_liquidity_management | — | — |
| oracle | banking_liquidity_management | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | blockchain_platform | < 21.1.2 | 21.1.2 |
| oracle | communications_calendar_server | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_oracle8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Unsafe Deserialization in jackson-databind
ghsa·2021-12-09
CVE-2020-24750 [HIGH] CWE-502 Unsafe Deserialization in jackson-databind
Unsafe Deserialization in jackson-databind
FasterXML jackson-databind 2.x before 2.6.7.5 and from 2.7.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
OSV
Unsafe Deserialization in jackson-databind
osv·2021-12-09
CVE-2020-24750 [HIGH] Unsafe Deserialization in jackson-databind
Unsafe Deserialization in jackson-databind
FasterXML jackson-databind 2.x before 2.6.7.5 and from 2.7.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
OSV
CVE-2020-24750: FasterXML jackson-databind 2
osv·2020-09-17·CVSS 8.1
CVE-2020-24750 [HIGH] CVE-2020-24750: FasterXML jackson-databind 2
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (jackson-databind) — CVE-2020-24750
vendor_oracle·2022-04-15·CVSS 8.1
CVE-2020-24750 [HIGH] Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (jackson-databind) — CVE-2020-24750
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (jackson-databind) vulnerability
CVE: CVE-2020-24750
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: PresenceApi (jackson-databind) — CVE-2020-24750
vendor_oracle·2022-01-15·CVSS 8.1
CVE-2020-24750 [HIGH] Oracle Oracle Communications Applications Risk Matrix: PresenceApi (jackson-databind) — CVE-2020-24750
Oracle Oracle Communications Applications Risk Matrix: PresenceApi (jackson-databind) vulnerability
CVE: CVE-2020-24750
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Security (jackson-databind) — CVE-2020-24750
vendor_oracle·2021-10-15·CVSS 8.1
CVE-2020-24750 [HIGH] Oracle Oracle Communications Risk Matrix: Security (jackson-databind) — CVE-2020-24750
Oracle Oracle Communications Risk Matrix: Security (jackson-databind) vulnerability
CVE: CVE-2020-24750
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Onboarding (jackson-databind) — CVE-2020-24750
vendor_oracle·2021-07-15·CVSS 8.1
CVE-2020-24750 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Onboarding (jackson-databind) — CVE-2020-24750
Oracle Oracle Financial Services Applications Risk Matrix: Onboarding (jackson-databind) vulnerability
CVE: CVE-2020-24750
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Event Reminders (jackson-databind) — CVE-2020-24750
vendor_oracle·2021-04-15·CVSS 8.1
CVE-2020-24750 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Event Reminders (jackson-databind) — CVE-2020-24750
Oracle Oracle Communications Applications Risk Matrix: Event Reminders (jackson-databind) vulnerability
CVE: CVE-2020-24750
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Communications Risk Matrix: IDIH (jackson-databind) — CVE-2020-24750
vendor_oracle·2021-01-15·CVSS 8.1
CVE-2020-24750 [HIGH] Oracle Oracle Communications Risk Matrix: IDIH (jackson-databind) — CVE-2020-24750
Oracle Oracle Communications Risk Matrix: IDIH (jackson-databind) vulnerability
CVE: CVE-2020-24750
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Red Hat
jackson-databind: Serialization gadgets in com.pastdev.httpcomponents.configuration.JndiConfiguration
vendor_redhat·2020-09-18·CVSS 8.1
CVE-2020-24750 [HIGH] CWE-502 jackson-databind: Serialization gadgets in com.pastdev.httpcomponents.configuration.JndiConfiguration
jackson-databind: Serialization gadgets in com.pastdev.httpcomponents.configuration.JndiConfiguration
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
A flaw was found in jackson-databind 2.x in versions prior to 2.9.10.6. The interaction between serialization gadgets and typing is mishandled. The highest threat from this vulnerability is to data confidentiality and system availability.
Statement: The following Red Hat products do ship the vulnerable component, but do not enable the unsafe conditions needed to exploit:
* JBoss Data Grid 7
* Business Process Management Suite 6
* Business Rules Management Suite 6
* JBoss Data Virtualization 6
* OpenShif
Debian
CVE-2020-24750: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee...
vendor_debian·2020·CVSS 8.1
CVE-2020-24750 [HIGH] CVE-2020-24750: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction betwee...
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
Scope: local
bookworm: resolved (fixed in 2.12.1-1)
bullseye: resolved (fixed in 2.12.1-1)
forky: resolved (fixed in 2.12.1-1)
sid: resolved (fixed in 2.12.1-1)
trixie: resolved (fixed in 2.12.1-1)
No detection rules found.
Exploit-DB
BSA Radar 1.6.7234.24750 - Local File Inclusion
exploitdb·2020-07-14·CVSS 4.3
CVE-2020-14946 [MEDIUM] BSA Radar 1.6.7234.24750 - Local File Inclusion
BSA Radar 1.6.7234.24750 - Local File Inclusion
---
# Exploit title: BSA Radar 1.6.7234.24750 - Local File Inclusion
# Date: 2020-07-08
# Exploit Author: William Summerhill
# Vendor homepage: https://www.globalradar.com/
# Version: BSA Radar - Version 1.6.7234.24750 and lower
# CVE-2020-14946 - Local File Inclusion
# Description: The Administrator section of the Surveillance module in Global RADAR - BSA Radar 1.6.7234.X
# and lower allows users to download transaction files. When downloading the files,
# a user is able to view local files on the web server by manipulating the FileName
# and FilePath parameters in the URL, or while using a proxy. This vulnerability could
# be used to view local sensitive files or configuration files on the backend server.
Vulnerable endpoint: /UC/downlo
Exploit-DB
BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password)
exploitdb·2020-07-08·CVSS 9.8
CVE-2020-14944 [CRITICAL] BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password)
BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password)
---
# Exploit title: BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password)
# Exploit Author: William Summerhill
# Date: 2020-06-22
# Vendor Homepage:bhttps://www.globalradar.com/
# Version: BSA Radar - Version 1.6.7234.24750 and lower
# CVE: CVE-2020-14944
# Description: The Global RADAR BSA Radar 1.6.7234.X application lacks valid authorization
# controls in multiple functions while logged into the application.
# This can allow for manipulation and takeover of user accounts if successfully exploited.
# The following vulnerable functions are exposed: ChangePassword, SaveUserProfile, GetUser
Proof of Concept:
1. ChangePassword API endpoint - Allows the ability to update the password belonging to
Exploit-DB
BSA Radar 1.6.7234.24750 - Authenticated Privilege Escalation
exploitdb·2020-07-07·CVSS 8.8
CVE-2020-14945 [HIGH] BSA Radar 1.6.7234.24750 - Authenticated Privilege Escalation
BSA Radar 1.6.7234.24750 - Authenticated Privilege Escalation
---
# Exploit Title: BSA Radar 1.6.7234.24750 - Authenticated Privilege Escalation
# Date: 2020-07-06
# Exploit Author: William Summerhill
# Vendor homepage: https://www.globalradar.com/
# Version: BSA Radar - Version 1.6.7234.24750 and lower
# CVE-2020-14945 - Privilege Escalation
Description: A privilege escalation vulnerability exists within Global RADAR BSA Radar 1.6.7234.X that allows an authenticated, low-privileged user to escalate their privileges to administrator rights (i.e. the "BankAdmin" role) via a forged request to the SaveUser API.
Proof of Concept:
The privilege escalation is achieved by saving the response of the GetUser request (from clicking the username in the top right). When this profile is saved it wil
Exploit-DB
BSA Radar 1.6.7234.24750 - Persistent Cross-Site Scripting
exploitdb·2020-06-24·CVSS 5.4
CVE-2020-14943 [MEDIUM] BSA Radar 1.6.7234.24750 - Persistent Cross-Site Scripting
BSA Radar 1.6.7234.24750 - Persistent Cross-Site Scripting
---
# Exploit title: BSA Radar 1.6.7234.24750 - Persistent Cross-Site Scripting
# Exploit Author: William Summerhill
# Date: 2020-06-22
# Vendor homepage: https://www.globalradar.com/
# Tested on: Window
# CVE-2020-14943
# Description: The "Firstname" and "Lastname" parameters in Global RADAR BSA Radar 1.6.7234.X
# are vulnerable to a stored Cross-Site Scripting (XSS) via the Update User Profile feature
# (in the top-right of the application).
# Proof of Concept:
Using the "update user profile" feature in the top-right of the application while logged in,
a malicious user can inject malicious, unencoded scripts, such as "alert(1)",
into the Firstname and Lastname parameters of a user account. This stored XSS will execute on
nea
Bugzilla
CVE-2020-24750 jackson-databind: mishandles the interaction between serialization gadgets and typing [fedora-all]
bugzilla·2020-09-24·CVSS 8.1
CVE-2020-24750 [HIGH] CVE-2020-24750 jackson-databind: mishandles the interaction between serialization gadgets and typing [fedora-all]
CVE-2020-24750 jackson-databind: mishandles the interaction between serialization gadgets and typing [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2020-24750 jackson-databind: Serialization gadgets in com.pastdev.httpcomponents.configuration.JndiConfiguration
bugzilla·2020-09-24·CVSS 8.1
CVE-2020-24750 [HIGH] CVE-2020-24750 jackson-databind: Serialization gadgets in com.pastdev.httpcomponents.configuration.JndiConfiguration
CVE-2020-24750 jackson-databind: Serialization gadgets in com.pastdev.httpcomponents.configuration.JndiConfiguration
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
Upstream bug:
https://github.com/FasterXML/jackson-databind/issues/2798
Upstream commits:
https://github.com/FasterXML/jackson-databind/commit/6cc9f1a1af323cd156f5668a47e43bab324ae16f
https://github.com/FasterXML/jackson-databind/commit/ad5a630174f08d279504bc51ebba8772fd71b86b
Discussion:
Created jackson-databind tracking bugs for this issue:
Affects: fedora-all [bug 1882313]
---
Mitigation:
The following conditions are needed for an exploit, we recommend avoiding all if possible:
*
arXiv
Revisiting Third-Party Library Detection: A Ground Truth Dataset and Its Implications Across Security Tasks
arxiv_fulltext·2025-09-05
Revisiting Third-Party Library Detection: A Ground Truth Dataset and Its Implications Across Security Tasks
## Abstract
Accurate detection of third-party libraries (TPLs) is fundamental to Android security, supporting vulnerability tracking, malware detection, and supply chain auditing.
Despite many proposed tools, their real-world effectiveness remains unclear.
We present the first large-scale empirical study of ten state-of-the-art TPL detection techniques across over 6,000 apps, enabled by a new ground truth dataset with precise version-level annotations for both remote and local dependencies.
Our evaluation exposes tool fragility to R8-era transformations, weak version discrimination, inaccurate correspondence of candidate libraries, difficulty in generalizing similarity thresholds, and prohibitive runtime/memory overheads at scale.
Beyond tool assessment, we further analyze how TPLs shape
https://github.com/FasterXML/jackson-databind/commit/ad5a630174f08d279504bc51ebba8772fd71b86bhttps://github.com/FasterXML/jackson-databind/issues/2798https://lists.debian.org/debian-lts-announce/2021/04/msg00025.htmlhttps://security.netapp.com/advisory/ntap-20201009-0003/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://github.com/FasterXML/jackson-databind/commit/ad5a630174f08d279504bc51ebba8772fd71b86bhttps://github.com/FasterXML/jackson-databind/issues/2798https://lists.debian.org/debian-lts-announce/2021/04/msg00025.htmlhttps://security.netapp.com/advisory/ntap-20201009-0003/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-09-17
Published