Back

HIGH

jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool

Published Dec 27, 2020

Description

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).

Affected products

Remediation

Red Hat statement

The following Red Hat Products ship jackson-databind version 2.10.0 or later which is not considered affected by this CVE (see https://medium.com/@cowtowncoder/jackson-2-10-safe-default-typing-2d018f0ce2ba) * JBoss Data Grid 7 * JBoss Data Grid 8 * Enterprise Application Platform 7 * Red Hat Decision Manager 7 * Red Hat Process Automation Manager 7 * Red Hat Single Sign-On (RH-SSO) 7 * Red Hat JBoss Fuse 7 * Red Hat JBoss A-MQ * Red Hat Enterprise Linux 8 * Red Hat Satellite 6.6 * Red Hat Satellite 6.7 * Red Hat Satellite 6.8 * Red Hat CodeReady Studio 12 Red Hat OpenShift Container Platform and Red Hat OpenStack Platform does ship the vulnerable components, but does not enable the unsafe conditions needed to exploit, lowering their vulnerability impact. In Red Hat Openshift 4 there are no plans to maintain the ose-logging-elasticsearch5 container, hence it has been marked wontfix at this time and may be fixed in a future update. Red Hat OpenStack Platform 13 ships OpenDaylight, which contains the vulnerable jackson-databind, but does not expose jackson-databind in a way that would make it exploitable. As such, Red Hat will not be providing a fix for OpenDaylight at this time.

Red Hat mitigation

The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS` * avoid com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool in the classpath

References (19)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Dec 27, 2020
Updated Aug 27, 2025
Reserved Dec 27, 2020

CISA Vulnrichment

Updated Aug 27, 2025

NVD

Status Analyzed
Modified Aug 25, 2026

Red Hat

Severity Important
Public date Dec 23, 2020
Bugzilla 1911502

ENISA EUVD

Assigner mitre
Published Dec 27, 2020
Updated Aug 27, 2025