Deserialization Flaw in Jackson Databind Affects Apache Ignite and Quartz Projects
CVE-2020-10650
What is CVE-2020-10650?
A deserialization vulnerability has been identified in the Jackson Databind library, present in version 2.9.10.4. This flaw could allow untrusted users to execute arbitrary code through specific classes utilized in Apache Ignite and Quartz frameworks, namely 'org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup', 'org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory', and 'org.quartz.utils.JNDIConnectionProvider'. If exploited, this could potentially lead to unauthorized actions within the application. Users should evaluate their systems and apply relevant mitigations or updates as needed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
