CVE-2019-12384Medium· 5.9▾ TwilightPoC availableFasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code exec…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 32.5 · likelihood 9 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
45%
2 GitHub repos (last check)
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.
jackson-databind >= 2.0.0, < 2.6.7.3jackson-databind >= 2.7.0, < 2.7.9.6jackson-databind >= 2.8.0, < 2.8.11.4jackson-databind >= 2.9.0, < 2.9.9.1debian_linux = 8.0enterprise_linux = 7.0enterprise_linux = 7.4enterprise_linux = 7.5enterprise_linux = 7.6enterprise_linux = 7.7Upgrade past the affected range:
jackson-databind 2.9.9.1Connected by shared product, vendor, weakness, or advisory.
CVE-2020-11113High· 8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2019-14893Critical· 9.8A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic ty…
CVE-2019-20330Critical· 9.8FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CVE-2020-11112High· 8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVE-2020-11111High· 8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVE-2020-10969High· 8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.