CVE-2020-10968
Java vulnerability analysis and mitigation

Overview

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy). The vulnerability was discovered and reported by XuYuanzhen of Alibaba Cloud Security Team (CVE Details).

Technical details

The vulnerability exists in the interaction between serialization gadgets and typing functionality in jackson-databind versions prior to 2.9.10.4. The specific issue relates to the handling of org.aoju.bus.proxy.provider.remoting.RmiProvider class. Starting from 2.10 series, this vulnerability is mitigated as Safe Default Typing is enabled by default, but it remains an issue when Default Typing is explicitly enabled (Jackson Blog).

Impact

A successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). The vulnerability has a CVSS v3.1 Base Score of 8.8 (High), indicating significant potential impact on confidentiality, integrity and availability (NetApp Advisory).

Mitigation and workarounds

The primary mitigation is to upgrade jackson-databind to version 2.9.10.4 or later. For users on version 2.10 and above, the vulnerability is mitigated by default due to Safe Default Typing being enabled. However, if Default Typing is explicitly enabled, the vulnerability may still be present. Organizations should review their jackson-databind implementation and ensure they are using the latest patched version (GitHub Issue).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management