cbcvebase.
CVE-2019-14892
published 2020-03-02

CVE-2019-14892: A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious…

PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.62%
92.7th percentile
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.

Affected

18 ranges
VendorProductVersion rangeFixed in
apachegeode——
debianjackson-databind< jackson-databind 2.10.0-1 (bookworm)jackson-databind 2.10.0-1 (bookworm)
fasterxmljackson-databind>= 0 < 2.10.0-12.10.0-1
fasterxmljackson-databind>= 0 < 2.10.0-12.10.0-1
fasterxmljackson-databind>= 0 < 2.10.0-12.10.0-1
fasterxmljackson-databind>= 0 < 2.10.0-12.10.0-1
fasterxmljackson-databind>= 2.0.0 < 2.6.7.32.6.7.3
fasterxmljackson-databind>= 2.7.0 < 2.8.11.52.8.11.5
fasterxmljackson-databind>= 2.9.0 < 2.9.102.9.10
red_hatjackson-databind——
red_hatjackson-databind——
red_hatjackson-databind——
redhatdecision_manager——
redhatjboss_data_grid——
redhatjboss_enterprise_application_platform——
redhatjboss_fuse——
redhatopenshift_container_platform——
redhatprocess_automation——

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://github.com/FasterXML/jackson-databind/commit/41b7f9b90149e9d44a65a8261a8deedc7186f6af↗
urlhttps://github.com/FasterXML/jackson-databind/commit/819cdbcab51c6da9fb896380f2d46e9b7d4fdc3b↗
  • →The vulnerability requires polymorphic deserialization to be enabled in jackson-databind. Detect JSON payloads referencing commons-configuration 1 or 2 JNDI classes in type metadata fields (e.g., '@class', '@type') as indicators of exploitation attempts. ↗
  • →New serialization gadgets were identified in commons-configuration 1 and commons-configuration 2 packages. Monitor deserialization activity involving these packages in applications using jackson-databind versions before 2.9.10, 2.8.11.5, or 2.6.7.3. ↗
  • ·Exploitation requires polymorphic unmarshalling to be explicitly enabled in the application's jackson-databind configuration. Applications that do not enable this feature are not vulnerable. ↗
  • ·OpenDaylight ships the vulnerable jackson-databind but does not expose it in a way that makes it exploitable, reducing real-world risk in that deployment context. ↗
  • ·OpenShift Container Platform elasticsearch plugins ship the vulnerable component but do not perform the unsafe operations required for exploitation. ↗

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.