CVE-2020-11113: High severity fasterxml jackson-databind vulnerability
A flaw was found in jackson-databind 2.x in versions prior to 2.9.10.4. The interaction between serialization gadgets and typing is mishandled. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
A vulnerability was found in Jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
— Red Hat
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-11113.
What is the severity of CVE-2020-11113?
CVE-2020-11113 has a severity rating of 9.8, which is considered critical.
What software is affected by CVE-2020-11113?
The following software versions are affected: Jackson-databind 2.x before 2.9.10.4, qpid-cpp 0:1.36.0-31.el6_10a, qpid-proton 0:0.32.0-1.el6_10, qpid-cpp 0:1.36.0-31.el7a, qpid-proton 0:0.32.0-2.el7, nodejs-rhea 0:1.0.24-1.el8, qpid-proton 0:0.32.0-2.el8, rh-maven35-jackson-databind 0:2.7.6-2.9.el7, IBM Disconnected Log Collector v1.0 - v1.8.2.
How does CVE-2020-11113 allow for code execution?
CVE-2020-11113 allows for code execution through unsafe deserialization in org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
Is there a fix available for CVE-2020-11113?
Yes, the fix for CVE-2020-11113 is to upgrade to version 2.9.10.4 of Jackson-databind.