← Back
Web Application
CVE-2020-10968 high CVSS 8.8

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).

Summary

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).

AI summary openai / gpt-4o

FasterXMLのjackson-databindにおけるバージョン2.x(2.9.10.4未満)には、シリアライゼーションガジェットと型付けの間の相互作用を誤って処理する脆弱性があります。これはorg.aoju.bus.proxy.provider.remoting.RmiProviderに関連しています。これにより、リモートコード実行(RCE)の危険があるため、深刻な問題です。修正は2.9.10.4バージョンで行われています。
❓ What is the problem
FasterXML jackson-databindのシリアライゼーションガジェットと型付けの処理に関する脆弱性
📍 Affected scope
バージョン2.x(2.9.10.4未満)のFasterXML jackson-databind
🔥 Severity
リモートコード実行(RCE)の危険性があり、重大です。
🔧 How to fix
jackson-databindをバージョン2.9.10.4にアップデートしてください。
🛡️ Workaround
情報なし
🔍 Detection
影響するバージョンを使用している場合、RmiProviderの利用に注意が必要です。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →