跳转到帖子

Debian: CVE-2020-10650: jackson-databind -- security update

recommended_posts

发布于
  • Members

Debian: CVE-2020-10650: jackson-databind -- security update

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
12/26/2022
Created
05/05/2023
Added
05/02/2023
Modified
01/28/2025

Description

A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.

Solution(s)

  • debian-upgrade-jackson-databind

References

  • https://attackerkb.com/topics/cve-2020-10650
  • CVE - 2020-10650
  • DLA-3407-1
  • 查看数 694
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…