CVE-2019-14892
published 2020-03-02CVE-2019-14892: A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.62%
92.1th percentile
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | geode | — | — |
| debian | jackson-databind | < jackson-databind 2.10.0-1 (bookworm) | jackson-databind 2.10.0-1 (bookworm) |
| fasterxml | jackson-databind | >= 0 < 2.10.0-1 | 2.10.0-1 |
| fasterxml | jackson-databind | >= 0 < 2.10.0-1 | 2.10.0-1 |
| fasterxml | jackson-databind | >= 0 < 2.10.0-1 | 2.10.0-1 |
| fasterxml | jackson-databind | >= 0 < 2.10.0-1 | 2.10.0-1 |
| fasterxml | jackson-databind | >= 2.0.0 < 2.6.7.3 | 2.6.7.3 |
| fasterxml | jackson-databind | >= 2.7.0 < 2.8.11.5 | 2.8.11.5 |
| fasterxml | jackson-databind | >= 2.9.0 < 2.9.10 | 2.9.10 |
| red_hat | jackson-databind | — | — |
| red_hat | jackson-databind | — | — |
| red_hat | jackson-databind | — | — |
| redhat | decision_manager | — | — |
| redhat | jboss_data_grid | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_fuse | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | process_automation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability requires polymorphic deserialization to be enabled in jackson-databind. Detect JSON payloads referencing commons-configuration 1 or 2 JNDI classes in type metadata fields (e.g., '@class', '@type') as indicators of exploitation attempts. ↗
- →New serialization gadgets were identified in commons-configuration 1 and commons-configuration 2 packages. Monitor deserialization activity involving these packages in applications using jackson-databind versions before 2.9.10, 2.8.11.5, or 2.6.7.3. ↗
- ·Exploitation requires polymorphic unmarshalling to be explicitly enabled in the application's jackson-databind configuration. Applications that do not enable this feature are not vulnerable. ↗
- ·OpenDaylight ships the vulnerable jackson-databind but does not expose it in a way that makes it exploitable, reducing real-world risk in that deployment context. ↗
- ·OpenShift Container Platform elasticsearch plugins ship the vulnerable component but do not perform the unsafe operations required for exploitation. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Polymorphic deserialization of malicious object in jackson-databind
osv·2020-05-15
CVE-2019-14892 [HIGH] Polymorphic deserialization of malicious object in jackson-databind
Polymorphic deserialization of malicious object in jackson-databind
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5, and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
GHSA
Polymorphic deserialization of malicious object in jackson-databind
ghsa·2020-05-15
CVE-2019-14892 [HIGH] CWE-200 Polymorphic deserialization of malicious object in jackson-databind
Polymorphic deserialization of malicious object in jackson-databind
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5, and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
OSV
CVE-2019-14892: A flaw was discovered in jackson-databind in versions before 2
osv·2020-03-02·CVSS 9.8
CVE-2019-14892 [CRITICAL] CVE-2019-14892: A flaw was discovered in jackson-databind in versions before 2
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
Red Hat
jackson-databind: Serialization gadgets in classes of the commons-configuration package
vendor_redhat·2019-09-19·CVSS 9.8
CVE-2019-14892 [CRITICAL] CWE-502 jackson-databind: Serialization gadgets in classes of the commons-configuration package
jackson-databind: Serialization gadgets in classes of the commons-configuration package
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
A flaw was discovered in jackson-databind, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
Statement: Satellite 6 does not enable polymorphic unmarshmalling, which is a required configuration for the vulnerability to be used. We may update the jackson-databind dependency in a future release.
Red Hat Ope
Debian
CVE-2019-14892: jackson-databind - A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 an...
vendor_debian·2019·CVSS 9.8
CVE-2019-14892 [CRITICAL] CVE-2019-14892: jackson-databind - A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 an...
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 2.10.0-1)
bullseye: resolved (fixed in 2.10.0-1)
forky: resolved (fixed in 2.10.0-1)
sid: resolved (fixed in 2.10.0-1)
trixie: resolved (fixed in 2.10.0-1)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2020:0729https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14892https://github.com/FasterXML/jackson-databind/issues/2462https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20200904-0005/https://access.redhat.com/errata/RHSA-2020:0729https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14892https://github.com/FasterXML/jackson-databind/issues/2462https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20200904-0005/
2020-03-02
Published