RULE(RULE ID:333524)

Rule General Information
Release Date: 2021-05-08
Rule Name: Insecure Java Deserialization Class JNDIConnectionSource Detection
Severity:
CVE ID:
Rule Protection Details
Description: In an unsafe JAVA deserialization class, its get or set method may have controllable parameters that lead to the execution of sensitive functions.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
https://github.com/FasterXML/jackson-databind/issues/2996
https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html
https://security.netapp.com/advisory/ntap-20210205-0005/
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://github.com/FasterXML/jackson-databind/issues/2996