Bugzilla – Bug 1167409
VUL-0: CVE-2020-10673: jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution
Last modified: 2020-03-23 10:13:48 UTC
CVE-2020-10673 A vulnerability was found in Jackson-databind 2.x before 2.9.10.4, where it mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef which could result in remote command execution References: https://bugzilla.redhat.com/show_bug.cgi?id=1815470 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-10673 http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-10673.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10673 https://github.com/FasterXML/jackson-databind/issues/2660 https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
jackson-databind in SLE-15-SP2 is at version 2.10.2 which is not affected by this issue.