← Back

CVE-2020-10650

nvd nist
Published: Dec 26, 2022Modified: Aug 19, 2025

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.

Affected (10)

Show all products
1 product
Debian Linux
1 product
Active Iq Unified Manager
1 product
Jackson Databind
2 products
Retail Merchandising System
Retail Sales Audit
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Netapp
All versions
All versions
All versions
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Fasterxml
Before 2.9.10.4
Version 2.10.0 prerelease1
Version 2.10.0 prerelease2
Version 2.10.0 prerelease3
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.0
Version 14.1

References (16)

Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.