Lucene search

K
redhatcveRedhat.comRH:CVE-2020-10969
HistoryMay 14, 2022 - 11:39 a.m.

CVE-2020-10969

2022-05-1411:39:50
redhat.com
access.redhat.com
25

0.008 Low

EPSS

Percentile

81.6%

A flaw was found in jackson-databind 2.x in versions prior to 2.9.10.4. The interaction between serialization gadgets and typing is mishandled. The highest threat from this vulnerability is to data confidentiality.

Mitigation

The following conditions are needed for an exploit, we recommend avoiding all if possible

  • Deserialization from sources you do not control
  • enableDefaultTyping()
  • @JsonTypeInfo using id.CLASSorid.MINIMAL_CLASS`