CVE-2019-14892Critical· 9.8▾ MidnightA flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use th…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 1.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
5.6%
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
jackson-databind >= 2.0.0, < 2.6.7.3jackson-databind >= 2.7.0, < 2.8.11.5jackson-databind >= 2.9.0, < 2.9.10decision_manager = 7.0jboss_data_gridjboss_data_grid = 7.0.0jboss_enterprise_application_platform = 7.0jboss_fuse = 7.0.0openshift_container_platform = 4.3process_automation = 7.0geode = 1.12.0Upgrade past the affected range:
jackson-databind 2.9.10Connected by shared product, vendor, weakness, or advisory.
CVE-2019-14893Critical· 9.8A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic ty…
CVE-2019-20330Critical· 9.8FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CVE-2020-8840Critical· 9.8FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
CVE-2019-16942Critical· 9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10
CVE-2019-17531Critical· 9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10
CVE-2019-14540Critical· 9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10