PT-2020-4193 · Apache+3 · Apache Xalan+3

Published

2020-06-14

·

Updated

2025-01-28

·

CVE-2020-14060

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: FasterXML jackson-databind versions 2.x before 2.9.10.5
Description: The issue is related to the deserialization mechanism in the FasterXML jackson-databind library, specifically with the oadd.org.apache.xalan.lib.sql.JNDIConnectionPool component. This can allow a remote attacker to execute arbitrary code. The problem arises from the interaction between serialization gadgets and typing.
Recommendations: For FasterXML jackson-databind versions 2.x before 2.9.10.5, update to version 2.9.10.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the oadd.org.apache.xalan.lib.sql.JNDIConnectionPool component until a patch is applied.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1792
BDU:2020-04627
CVE-2020-14060
DLA-2270-1
GHSA-J823-4QCH-3RGM
MGASA-2021-0153
ROSA-SA-2025-2629
USN-4813-1

Affected Products

Alt Linux
Apache Xalan
Ubuntu
Jackson-Databind