Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2020-10673 — CVE-2020-10673 | Kitploit
Tools/GitHubGitHub/harry1080/cve-2020-10673
Static AnalysisVulnerability AnalysisCode AnalysisExploitationWeb Application Exploitation
GitHubharry1080/cve-2020-10673

CVE-2020-10673

CVE-2020-10673

View Repository
256 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Vulnerability Description

Recently, the Asiainfo Security Network Attack and Defense Laboratory tracked that jackson-databind has updated a JNDI injection blacklist class. If the jar package of this class exists in the project and the JDK version meets the injection version, remote code execution can be achieved through JNDI injection. The class is com.caucho.config.types.ResourceRef.

Vulnerability IDs:

  • CVE-2020-10673
  • Jackson internal ID 2660

Affected Versions

  • jackson-databind <= 2.10.3

  • fastjson <= 1.2.66

Fix Recommendations

The official fix patch has been released. Please go to

https://github.com/alibaba/fastjson/releases

page to download the latest version.

References

  • Security Bulletin: Fastjson releases high-risk vulnerability patch
  • Vulnerability Advisory: CVE-2020-10673/jackson-databind JNDI Injection leads to Remote Code Execution
Download Tool