CVE-2020-10650: Debian Linux

High severity, CVSS 8.1. EPSS: 3.5% chance of exploitation in the next 30 days.

A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jta.jndi.CacheJndiTmFactory, and org.quartz.utils.JNDIConnectionProvider.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fasterxml Jackson-Databind: before 2.9.10.4 (fixed in 2.9.10.4); version 2.10.0 only
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Oracle Retail Merchandising System: version 15.0 only
  • Oracle Retail Sales Audit: version 14.1 only

Published 2022-12-26. Last modified 2026-06-17.