CVE-2020-10650
26.12.2022, 20:15
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.Enginsight
Vendor | Product | Version |
---|---|---|
fasterxml | jackson-databind | 𝑥 ≤ 2.9.10.4 |
oracle | retail_merchandising_system | 15.0 |
oracle | retail_sales_audit | 14.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References