← Back
Web Application
CVE-2020-11113 high CVSS 8.8

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).

Summary

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).

AI summary openai / gpt-4o

FasterXML jackson-databindのバージョン2.xは、2.9.10.4より前のバージョンで、シリアル化ガジェットとタイプの間の相互作用を誤処理しています。openjpaライブラリの特定機能が悪用される可能性があります。この脆弱性により、攻撃者はリモートコード実行を行う可能性があります。ユーザーはすぐに最新のパッチを適用することが推奨されます。
❓ What is the problem
FasterXML jackson-databindのシリアル化ガジェットとタイプの間の誤処理。
📍 Affected scope
バージョン2.x(2.9.10.4未満)。
🔥 Severity
リモートコード実行の可能性があり、非常に重大。
🔧 How to fix
バージョン2.9.10.4以降に更新する。
🛡️ Workaround
情報なし。
🔍 Detection
使用しているジャクソンライブラリのバージョンを確認し、影響を受けるかを判断する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →