CVE-2020-8840 - MergeBase Vulnerability Database
Risk Score
9.8
Out of 10
Summary
Published
Feb 10, 2020
Updated
Feb 22, 2021
Source
NVD
Identifier

CVE-2020-8840

Description
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
MergeBase Comment
The CVE description makes it sound like version 2.9.10.3 and newer contains a more general defense against "xbean-reflect/JNDI" attacks, but in truth it's just a blacklist entry added for org.apache.xbean.propertyeditor.JndiConverter. See for yourself!
 
git clone https://github.com/FasterXML/jackson-databind.git
git log -p --first-parent jackson-databind-2.9.10.2..jackson-databind-2.9.10.3 -- src/main

| +        // [databind#2620]: xbean-reflect
| +        s.add("org.apache.xbean.propertyeditor.JndiConverter");
| +

Jackson-databind probably has more CVEs than any other open source Java library on the planet. But that is a bit misleading, because the CVE's tend to be associated with blacklist "gadget" entries added to jackson-databind's list of Java objects it will refuse to deserialize against. A good blog post at cowtowncoder.medium.com explains this in more detail.

Common Weakness Enumeration (CWE)

Discover More from MergeBase

Open Source Protection

Stay on top of the real risk of open source at any time.

Avoid false positives and get sophisticated upgrade guidance based on risk, compatibility and popularity.

More on Continuous Protection

Add RunTime Protection

Detect and defend against known-vulnerabilities at runtime. The only SCA to do so.

The quickest way to respond to an imminent threat like log4j with CVE-2021-44228.

More on Run-time Protection

Shift Left Now

CodeGreen is an early-warning defence for your in-house development and integrates directly into GitHub and BitBucket

More on BitBucket and Github apps