Deserialization Flaw in Jackson Databind Affects Apache Ignite and Quartz Projects
CVE-2020-10650
8.1HIGH
What is CVE-2020-10650?
A deserialization vulnerability has been identified in the Jackson Databind library, present in version 2.9.10.4. This flaw could allow untrusted users to execute arbitrary code through specific classes utilized in Apache Ignite and Quartz frameworks, namely 'org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup', 'org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory', and 'org.quartz.utils.JNDIConnectionProvider'. If exploited, this could potentially lead to unauthorized actions within the application. Users should evaluate their systems and apply relevant mitigations or updates as needed.
