CVE-2020-24616: Code Injection
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-24616?
CVE-2020-24616 is a vulnerability in FasterXML jackson-databind that allows a remote attacker to execute arbitrary code on the system.
How does CVE-2020-24616 work?
CVE-2020-24616 is caused by an unsafe deserialization between gadgets and typing, specifically related to br.com.anteros.dbcp.AnterosDBCPDataSource.
Which software products are affected by CVE-2020-24616?
FasterXML jackson-databind versions before 2.9.10.6 are affected. Netapp Active Iq Unified Manager, Oracle Agile PLM, and Oracle Application Testing Suite are also affected.
What is the severity of CVE-2020-24616?
CVE-2020-24616 has a severity rating of 9.8 (critical).
How can I fix CVE-2020-24616?
To fix CVE-2020-24616, update FasterXML jackson-databind to version 2.9.10.6 or later.