Horizon Alert
Summary of the vulnerability and why it matters
A security issue has been identified in a widely used software component, which, under specific circumstances and with certain additional software present, could allow an attacker to execute malicious code. This could impact the integrity and availability of affected services. The primary concern is to determine if your environment utilizes the affected component and if the conditions for exploitation are present.
- A library flaw could enable code execution.
- Understand if this library is in use.
- Confirm relevance and assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by sending specially crafted JSON data to an exposed endpoint. If the application uses the jackson-databind library with default typing enabled and includes the p6spy jar, the attacker can leverage a Remote Method Invocation (RMI) service to execute arbitrary code. This attack path relies on the library's mishandling of polymorphic types when processing untrusted JSON input.
- Unauthenticated network access required.
- Malicious JSON triggers vulnerable type handling.
- Enables remote code execution.
Live Threat
Current exploitation, exposure, and threat context
When Default Typing is enabled for an external JSON endpoint and the `p6spy` library is present, an attacker could potentially execute malicious code by targeting an RMI service. This occurs due to how `com.p6spy.engine.spy.P6DataSource` handles certain data inputs.
- Server-side code execution.
- Via JSON parsing with specific setup.
- Compromise of service integrity.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in `jackson-databind` with `p6spy` in the classpath, when Default Typing is enabled, requires an attacker to access an RMI service endpoint to execute a malicious payload. Owners of applications using `jackson-databind` must first identify instances of this library, confirm exposure via RMI, and assess business criticality. Remediation planning should prioritize these exposed and critical systems.
- Application owners and platform teams.
- Confirm RMI service exposure and reachability.
- Plan remediation based on identified risk.