CVE-2020-10672 | FasterXML jackson-databind up to 2.9.10.3 Gadget Serialized Remote Code Execution (Issue 2659 / Nessus ID 216682)
A vulnerability classified as very critical was found in FasterXML jackson-databind up to 2.9.10.3. This affects an unknown function of the component Gadget Handler. The manipulation results in Remote Code Execution (Serialized).
This vulnerability is known as CVE-2020-10672. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.