A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Geode
APPApache1.12.0Fasterxml Jackson Databind
APPFasterxml2.7.0 – 2.8.11.5 (excl.)2.9.0 – 2.9.10 (excl.)2.0.0 – 2.6.7.3 (excl.)Red Hat Decision Manager
APPRedhat7.0Red Hat Jboss Data Grid
APPRedhat7.0.0Red Hat Jboss Enterprise Application Platform
APPRedhat7.0Red Hat Jboss Fuse
APPRedhat7.0.0Red Hat OpenShift Container Platform
APPRedhat4.3Red Hat Process Automation
APPRedhat7.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEDeserialization
References
Related vulnerabilities
CVE-2020-1938CRITICAL9.8⚠ KEVPL ✓same product
Apache Tomcat AJP Connector — odczyt plików i RCE (Ghostcat)
CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓same product
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓same product
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE
CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓same product
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)
CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓same product
RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework