跳转至

CVE-2020-36179〜82 Jackson-databind SSRF&RCE

  • CVE-2020-36179:
  • CVE-2020-36180
  • CVE-2020-36181
  • CVE-2020-36182

RCE:

PoC Github:https://github.com/Al1ex/CVE-2020-36179

本地复现成功:

https://forum.ywhack.com/attachments/month_2101/210111125772a8c5f2e87d1718.png

ref:

https://forum.ywhack.com/thread-114949-1-1.html