← Back
Web Application
CVE-2020-10672 high CVSS 8.8

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...

Summary

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).

AI summary openai / gpt-4o

FasterXMLのライブラリであるjackson-databindのバージョン2.9.10.4未満に、シリアライゼーションガジェットと型指定の不適切な処理による脆弱性が存在します。この脆弱性は、org.apache.aries.transaction.jms.internal.XaPooledConnectionFactoryに関連しています。攻撃者はこの脆弱性を利用して任意のコードを実行できる可能性があります。
❓ What is the problem
シリアライゼーションガジェットと型指定の不適切な処理に起因する脆弱性
📍 Affected scope
FasterXML jackson-databind 2.x (2.9.10.4未満)
🔥 Severity
攻撃者が任意コードを実行できる可能性があり、深刻な影響を及ぼす。
🔧 How to fix
jackson-databindをバージョン2.9.10.4以上にアップデートしてください。
🛡️ Workaround
情報なし
🔍 Detection
使用中のライブラリのバージョンが2.9.10.4未満であるかを確認する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →