Polymorphic deserialization of malicious object in jackson-databind
High severity
GitHub Reviewed
Published
May 15, 2020
to the GitHub Advisory Database
•
Updated Sep 14, 2023
Package
Affected versions
<= 2.6.7.2
>= 2.9.0, < 2.9.10
>= 2.7.0, <= 2.8.11.4
Patched versions
2.6.7.3
2.9.10
2.8.11.5
Description
Published by the National Vulnerability Database
Mar 2, 2020
Reviewed
Apr 23, 2020
Published to the GitHub Advisory Database
May 15, 2020
Last updated
Sep 14, 2023
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5, and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
References