CVE-2020-8840 is an unsafe deserialization vulnerability in FasterXML jackson-databind versions 2.0.0 through 2.9.10.2. Jackson Databind failed to block certain xbean-reflect/JNDI types from polymorphic deserialization, including org.apache.xbean.propertyeditor.JndiConverter. An application that deserializes attacker-controlled data with the requisite unsafe polymorphic-typing configuration can instantiate this gadget and trigger unintended behavior.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a proof-of-concept (POC) exploit for CVE-2020-8840, a remote code execution vulnerability in the FasterXML jackson-databind library. The repository contains a single Java file (Poc.java) that demonstrates how enabling default typing in ObjectMapper and deserializing a specially crafted JSON payload can trigger a JNDI lookup via the org.apache.xbean.propertyeditor.JndiConverter class. The payload references an LDAP endpoint (ldap://localhost:1389/ExportObject), which in a real attack scenario could be controlled by an attacker to deliver malicious objects and achieve remote code execution. The exploit does not include a malicious LDAP server or a full attack chain, but clearly demonstrates the vulnerability mechanism. The README provides a brief description and a reference image. The code is concise and focused solely on demonstrating the exploit vector.
This repository is a proof-of-concept (POC) exploit for a remote code execution (RCE) vulnerability in Alibaba Fastjson version 1.2.62 and below. The main file, 'poc.java', demonstrates how enabling autoType support in Fastjson allows an attacker to supply a specially crafted JSON payload. This payload leverages the 'org.apache.xbean.propertyeditor.JndiConverter' class to trigger a JNDI lookup via RMI (to rmi://127.0.0.1:1099/tr1ple). If the RMI server is controlled by an attacker, this can result in remote code execution on the vulnerable system. The repository includes a Maven configuration ('pom.xml') specifying the required dependencies, and a brief 'readme.md' referencing an external vulnerability analysis. The exploit is network-based, targeting Java applications that use Fastjson with unsafe configuration.
This repository is a proof-of-concept (POC) environment for demonstrating exploitation of CVE-2020-8840, a remote code execution vulnerability in jackson-databind (and also affecting Fastjson). The repository contains Java code to demonstrate the attack chain: 'FastjsonDemo.java' and 'JacksonDemo.java' are sample programs that trigger deserialization using attacker-supplied JSON payloads referencing a JNDI LDAP endpoint. The LDAP endpoint (e.g., ldap://localhost:1389/Evil) is expected to serve a malicious class file ('Evil.class'), which, when loaded, executes an arbitrary system command (opening Calculator.app on macOS as a demonstration). The repository also includes configuration files for a Java web application and instructions for setting up the required LDAP and HTTP servers. The exploit demonstrates how an attacker can achieve remote code execution by leveraging insecure deserialization in vulnerable versions of jackson-databind and Fastjson, provided that the target application enables certain features (e.g., auto type support). The code is not weaponized but provides a clear POC for the vulnerability.
This repository demonstrates a proof-of-concept exploit for CVE-2020-8840, a remote code execution vulnerability in FasterXML's jackson-databind library (versions 2.0.0 through 2.9.10.2) due to unsafe deserialization and JNDI injection. The repository contains two Java files: 'Poc.java', which acts as the exploit driver, and 'exp/Exploit.java', which is the malicious class intended to be loaded via JNDI. The exploit chain involves setting up an LDAP server (using marshalsec) that points to a web server hosting the compiled 'Exploit' class. When the vulnerable application deserializes a crafted JSON payload referencing 'org.apache.xbean.propertyeditor.JndiConverter', it triggers a JNDI lookup to the attacker's LDAP server, which in turn loads the malicious class and executes arbitrary code (in this case, launching Calculator.app on macOS). The README provides detailed setup and exploitation instructions, including environment requirements and mitigation advice. The exploit is a proof-of-concept and demonstrates the risk of unsafe deserialization in Java applications using jackson-databind.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability referenced by the CIQ crlsa-2020_1644 security update; the content assigns it a CVSS v2 base score of 7.5 but provides no technical details.
A Jackson Databind flaw caused by insufficient blocking of certain xbean-reflect/JNDI functionality.
A Jackson Databind flaw caused by missing blocking of certain xbean-reflect/JNDI functionality.
Jackson Databind incomplete blacklist flaw for xbean-reflect/JNDI classes, creating unsafe deserialization risk.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.