
CVE-2020-10673
Recently, the Asiainfo Security Network Attack and Defense Laboratory tracked that jackson-databind has updated a JNDI injection blacklist class. If the jar package of this class exists in the project and the JDK version meets the injection version, remote code execution can be achieved through JNDI injection. The class is com.caucho.config.types.ResourceRef.
Vulnerability IDs:
jackson-databind <= 2.10.3
fastjson <= 1.2.66
The official fix patch has been released. Please go to
https://github.com/alibaba/fastjson/releases
page to download the latest version.