PT-2020-5468 · Fasterxml+3 · Jackson-Databind+3

Published

2020-01-31

·

Updated

2025-07-10

·

CVE-2020-10968

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FasterXML jackson-databind versions 2.x prior to 2.9.10.4
Description The issue is related to the interaction between serialization gadgets and typing in the FasterXML jackson-databind library, specifically with the org.aoju.bus.proxy.provider.remoting.RmiProvider component, also known as bus-proxy. This component is vulnerable to deserialization of untrusted data, which can lead to unauthorized access and manipulation of sensitive information. The vulnerability can be exploited remotely, potentially affecting the confidentiality, integrity, and availability of protected information.
Recommendations For FasterXML jackson-databind versions 2.x prior to 2.9.10.4, update to version 2.9.10.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the org.aoju.bus.proxy.provider.remoting.RmiProvider component until a patch is applied. Additionally, avoid using the org.aoju.bus.proxy.provider.remoting.RmiProvider component in sensitive environments until the issue is fully resolved.

Exploit

Fix

DoS

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1792
BDU:2021-00725
CVE-2020-10968
DLA-2179-1
GHSA-RF6R-2C4Q-2VWG
MGASA-2021-0153
RHSA-2020:1523
RHSA-2020:4366
ROSA-SA-2025-2629
USN-4813-1

Affected Products

Alt Linux
Red Os
Ubuntu
Jackson-Databind