Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability exists in a widely used Java library for processing JSON data, specifically when default typing is enabled for external data inputs and a particular logging library is present. This combination allows an attacker to potentially execute malicious code on affected systems.
- Allows code execution via data input.
- Leadership should remember it for data input risks.
- Confirm relevance and exposure of data processing.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this by sending specially crafted JSON data to an externally exposed endpoint. If the service uses `jackson-databind` with default typing enabled and has `apache-log4j-extra` in its classpath, the attacker can provide a JNDI service. This allows the service to execute arbitrary code with a malicious payload, leading to a compromise of the system.
- Attacker sends malicious JSON to an endpoint.
- Default typing and log4j-extra are enabled.
- Arbitrary code execution on the service.
Live Threat
Current exploitation, exposure, and threat context
When Default Typing is enabled for an externally exposed JSON endpoint and the `apache-log4j-extra` jar is present, an attacker could provide a JNDI service to execute a malicious payload. This could affect the availability and integrity of the affected service.
- System data and service behavior may be at risk.
- An attacker could exploit JNDI and JSON processing.
- The service could experience unauthorized code execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
The fasterxml jackson-databind vulnerability, when Default Typing is enabled and the `apache-log4j-extra` jar is present, can lead to malicious payload execution. Ownership typically falls to the application or platform teams responsible for services processing external JSON inputs. The first actionable step is to identify all instances of the affected library, determine their reachability and business criticality, and then prioritize remediation based on risk.
- Application and platform teams own remediation.
- Verify Default Typing enabled and log4j-extra presence.
- Plan remediation based on exposure and criticality.