Exploitation Summary
EIP tracks 9 public exploits for CVE-2020-8840. PoCs published by jas502n, fairyming, Wfzsec.
AI-analyzed exploit summary This repository contains a functional PoC for CVE-2020-8840, a deserialization vulnerability in FasterXML/jackson-databind. The exploit leverages the `JndiConverter` class to trigger an LDAP lookup, potentially leading to remote code execution if an attacker-controlled LDAP server is used.
Description
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
Exploits (9)
This repository contains a functional PoC for CVE-2020-8840, a deserialization vulnerability in FasterXML/jackson-databind. The exploit leverages the `JndiConverter` class to trigger an LDAP lookup, potentially leading to remote code execution if an attacker-controlled LDAP server is used.
This repository contains a functional PoC for CVE-2020-8840, a JNDI injection vulnerability in FasterXML/jackson-databind. The exploit leverages the `org.apache.xbean.propertyeditor.JndiConverter` class to trigger remote code execution via LDAP.
This repository contains a functional exploit PoC for CVE-2020-8840, demonstrating a deserialization vulnerability in Fastjson <= 1.2.62. The PoC leverages the JndiConverter class to trigger a JNDI lookup, potentially leading to remote code execution.
This repository contains a functional PoC for CVE-2020-8840, a deserialization vulnerability in Jackson Databind. The exploit leverages the `JndiConverter` class to trigger an LDAP connection to a malicious server, leading to arbitrary code execution via the `Evil` class.
This repository contains functional exploit code for CVE-2020-8840, demonstrating remote code execution via JNDI injection in Jackson-databind and Fastjson. It includes payloads, an evil class, and instructions for setting up LDAP and HTTP servers to trigger the vulnerability.
This repository contains a functional PoC for CVE-2020-8840, demonstrating deserialization vulnerabilities in Fastjson and Jackson libraries. The exploit leverages JNDI injection via LDAP to execute arbitrary code (e.g., launching Calculator.app).
This repository contains a functional PoC for CVE-2020-8840, a deserialization vulnerability in Jackson-databind. The exploit leverages JNDI injection via LDAP to achieve remote code execution by deserializing a malicious JSON payload.
This repository contains a vulnerable version of Jackson Databind (2.9.0) that demonstrates CVE-2020-8840, a deserialization vulnerability. The included source code and build configuration allow for testing and exploitation of the flaw.
This repository contains a vulnerable version of Jackson Databind (2.9.0) that demonstrates CVE-2020-8840, a deserialization vulnerability. The included source code and build configuration allow for testing and exploitation of the flaw.
References (44)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H