jackson-CVE-2020-8840
by jas502n
FasterXML/jackson-databind 远程代码执行漏洞
AI summary
Remote code execution vulnerability
A project that details and demonstrates the impact of a remote code execution vulnerability in a popular Java library used for JSON data binding.
- stars
- 73
- forks
- 16
- watching
- 2
Similar projects
Found by comparing what the projects do, not just their names.
RCE exploit
A proof-of-concept project demonstrating a Jackson RCE vulnerability in Ruby that allows an attacker to execute arbitrary commands on the system.
JSON parser exploit
This project demonstrates a remote code execution vulnerability in a popular JSON parsing library using a crafted input to exploit the RMI protocol.
Exploitation demo
A proof-of-concept project demonstrating exploitation of a vulnerability in Jackson-databind via Spring application contexts and expressions.
RCE vulnerability demonstration
A proof of concept project demonstrating a remote code execution vulnerability in Apache Solr via deserialization of untrusted data
RCE exploit
Exploits a remote code execution vulnerability in WebLogic Coherence using Java
RCE exploit
Exploiting a Remote Code Execution vulnerability in WebLogic T3/IIOP
Exploit code
An exploit for a Java vulnerability
Deserialization exploit
Reproducing and analyzing the CVE-2021-29505 vulnerability in Java's XStream deserialization process
Vulnerability scanner
Automated tool to identify vulnerabilities in Joomla components and generate reports
Deserialization vulnerability lab
A lab project providing code samples and tools to understand deserialization vulnerabilities in Java applications.
Vulnerability exploit
An exploit for a Java-based LDAP vulnerability
Java dev container
A sample project to try out development containers with Java
JSON documentation library
A comprehensive resource for learning and using the Jackson JSON processor
Browser vulnerability detector
A tool designed to emulate browser behavior and detect vulnerabilities in web-based exploits
Vulnerability scanner
A tool that scans websites for Log4j2 remote code execution vulnerabilities using multiple DNS log platforms and supports various scan types