Bugzilla – Bug 1168203
VUL-0: CVE-2020-10968: jackson-databind: serialization gadgets in bus-proxy
Last modified: 2020-03-31 14:52:23 UTC
rh#1819208 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy). Reference: https://github.com/FasterXML/jackson-databind/issues/2662 References: https://bugzilla.redhat.com/show_bug.cgi?id=1819208 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-10968 http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-10968.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10968 https://github.com/FasterXML/jackson-databind/issues/2662 https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
shipping 2.10.2, which is not affected.