Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-8840 PoC — FasterXML jackson-databind 代码问题漏洞

Source
Associated Vulnerability
Title:FasterXML jackson-databind 代码问题漏洞 (CVE-2020-8840)
Description:FasterXML jackson-databind是FasterXML公司的一个基于JAVA可以将XML和JSON等数据格式与JAVA对象进行转换的库。Jackson可以轻松的将Java对象转换成json对象和xml文档,同样也可以将json、xml转换成Java对象。 FasterXML jackson-databind 2.0.0版本至2.9.10.2版本中存在代码问题漏洞,该漏洞源于程序缺少xbean-reflect/JNDI黑名单类。攻击者可利用该漏洞执行代码。
Description
FasterXML/jackson-databind 远程代码执行漏洞
Readme
# CVE-2020-8840 FasterXML/jackson-databind 远程代码执行漏洞


![](./CVE-2020-8840.png	)
File Snapshot

[4.0K] /data/pocs/1bc78c93f095490f509939c08fb8e36ab831a8a1 ├── [712K] CVE-2020-8840.png ├── [4.0K] jar │   ├── [ 66K] jackson-annotations-2.10.1.jar │   ├── [340K] jackson-core-2.10.1.jar │   ├── [1.3M] jackson-databind-2.10.1.jar │   └── [155K] xbean-reflect-4.15.jar ├── [ 516] Poc.java └── [ 96] README.md 1 directory, 7 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.