Severity
9.8CRITICAL
EPSS
1.5%
top 19.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 29
Latest updateMar 14

Description

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages20 packages

NVDfasterxml/jackson-databind2.0.02.6.7.3+3
Debianjackson-databind< 2.9.9.3-1+3
NVDapple/xcode< 13.3

Also affects: Debian Linux 8.0, Fedora 29, 30, 31, Openshift Container Platform 3.11, 4.1

Patches

🔴Vulnerability Details

5
OSV
jackson-databind vulnerabilities2021-03-15
OSV
Deserialization of untrusted data in FasterXML jackson-databind2019-08-01
GHSA
Deserialization of untrusted data in FasterXML jackson-databind2019-08-01
CVEList
CVE-2019-14379: SubTypeValidator2019-07-29
OSV
CVE-2019-14379: SubTypeValidator2019-07-29

📋Vendor Advisories

7
Apple
CVE-2019-14379: Xcode 13.32022-03-14
Ubuntu
Jackson Databind vulnerabilities2021-03-15
Oracle
Oracle Oracle GoldenGate Risk Matrix: Security / Application Adapters (jackson-databind, SLF4J, ZooKeeper, Apache Spark) — CVE-2019-143792020-07-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (jackson-databind) — CVE-2019-143792020-04-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Presence-api (jackson-databind) — CVE-2019-143792020-01-15

💬Community

2
Bugzilla
CVE-2019-14379 jackson-databind: default typing mishandling leading to remote code execution2019-08-05
Bugzilla
CVE-2019-14379 jackson-databind: default typing mishandling leading to remote code execution [fedora-all]2019-08-05