CVE-2020-14060: High severity fasterxml jackson-databind vulnerability
A flaw was found in jackson-databind 2.x in versions prior to 2.9.10.5. The interaction between serialization gadgets and typing is mishandled. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
A Vulnerability was found in FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool
References: https://github.com/FasterXML/jackson-databind/issues/2688 https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
— Red Hat
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/candlepinto a version that resolves this vulnerability.Fixed in 0:2.6.16-1.el7 - Upgrade
Upgrade
redhat/foremanto a version that resolves this vulnerability.Fixed in 0:1.22.0.39-2.el7 - Upgrade
Upgrade
redhat/satelliteto a version that resolves this vulnerability.Fixed in 0:6.6.3-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-ovirtto a version that resolves this vulnerability.Fixed in 0:1.2.3-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-katelloto a version that resolves this vulnerability.Fixed in 0:3.12.0.41-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-runcibleto a version that resolves this vulnerability.Fixed in 0:2.13.0-1.el7 - Upgrade
Upgrade
redhat/candlepinto a version that resolves this vulnerability.Fixed in 0:2.9.28-1.el7 - Upgrade
Upgrade
redhat/foremanto a version that resolves this vulnerability.Fixed in 0:1.24.1.24-1.el7 - Upgrade
Upgrade
redhat/foreman-installerto a version that resolves this vulnerability.Fixed in 1:1.24.1.21-1.el7 - Upgrade
Upgrade
redhat/pulp-rpmto a version that resolves this vulnerability.Fixed in 0:2.21.0.6-1.el7 - Upgrade
Upgrade
redhat/satelliteto a version that resolves this vulnerability.Fixed in 0:6.7.2-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-vsphereto a version that resolves this vulnerability.Fixed in 0:3.2.1.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-foreman-tasksto a version that resolves this vulnerability.Fixed in 0:0.17.5.6-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-katelloto a version that resolves this vulnerability.Fixed in 0:3.14.0.25-1.el7 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.10.5 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.10.5 - Upgrade
Upgrade
FasterXML jackson-databind 2.xto a version that resolves this vulnerability.Fixed in 2.9.10.5 - Configuration
Avoid using enableDefaultTyping() (i.e., do not enable default typing) to prevent mishandling of the interaction between serialization gadgets and typing.
FasterXML jackson-databind enableDefaultTyping() = disable - Compensating control
Ensure the class oadd.org.apache.xalan.lib.sql.JNDIConnectionPool is not present on the application classpath to prevent the gadget interaction described for FasterXML jackson-databind 2.x before 2.9.10.5.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-14060?
CVE-2020-14060 is a vulnerability in jackson-databind 2.x before 2.9.10.5 that mishandles the interaction between serialization gadgets and typing.
What is the severity of CVE-2020-14060?
The severity of CVE-2020-14060 is high, with a CVSS score of 8.1.
How does CVE-2020-14060 impact data confidentiality and integrity?
CVE-2020-14060 can lead to data confidentiality and integrity issues.
How can I fix CVE-2020-14060?
To fix CVE-2020-14060, update jackson-databind to version 2.9.10.5 or higher.
Where can I find more information about CVE-2020-14060?
You can find more information about CVE-2020-14060 on the following references: [link1](https://github.com/FasterXML/jackson-databind/issues/2688), [link2](https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1848968)