Skip to main content
HIGH

CVE-2020-10650

CVSS v3

8.1

HIGH

EPSS Score

9.9 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.

Technical details

Published
2022-12-26

Frequently asked questions

What is CVE-2020-10650?

A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.

Is CVE-2020-10650 actively exploited?

Active exploitation of CVE-2020-10650 has not been confirmed. The EPSS score is 9.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-10650?

CVE-2020-10650 has a CVSS v3 base score of 8.1 (HIGH severity).

Is CVE-2020-10650 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key