cbcvebase.
CVE-2019-14892
published 2020-03-02

CVE-2019-14892: A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious…

PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.62%
92.1th percentile
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.

Affected

18 ranges
VendorProductVersion rangeFixed in
apachegeode
debianjackson-databind< jackson-databind 2.10.0-1 (bookworm)jackson-databind 2.10.0-1 (bookworm)
fasterxmljackson-databind>= 0 < 2.10.0-12.10.0-1
fasterxmljackson-databind>= 0 < 2.10.0-12.10.0-1
fasterxmljackson-databind>= 0 < 2.10.0-12.10.0-1
fasterxmljackson-databind>= 0 < 2.10.0-12.10.0-1
fasterxmljackson-databind>= 2.0.0 < 2.6.7.32.6.7.3
fasterxmljackson-databind>= 2.7.0 < 2.8.11.52.8.11.5
fasterxmljackson-databind>= 2.9.0 < 2.9.102.9.10
red_hatjackson-databind
red_hatjackson-databind
red_hatjackson-databind
redhatdecision_manager
redhatjboss_data_grid
redhatjboss_enterprise_application_platform
redhatjboss_fuse
redhatopenshift_container_platform
redhatprocess_automation

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://github.com/FasterXML/jackson-databind/commit/41b7f9b90149e9d44a65a8261a8deedc7186f6af
urlhttps://github.com/FasterXML/jackson-databind/commit/819cdbcab51c6da9fb896380f2d46e9b7d4fdc3b
  • The vulnerability requires polymorphic deserialization to be enabled in jackson-databind. Detect JSON payloads referencing commons-configuration 1 or 2 JNDI classes in type metadata fields (e.g., '@class', '@type') as indicators of exploitation attempts.
  • New serialization gadgets were identified in commons-configuration 1 and commons-configuration 2 packages. Monitor deserialization activity involving these packages in applications using jackson-databind versions before 2.9.10, 2.8.11.5, or 2.6.7.3.
  • ·Exploitation requires polymorphic unmarshalling to be explicitly enabled in the application's jackson-databind configuration. Applications that do not enable this feature are not vulnerable.
  • ·OpenDaylight ships the vulnerable jackson-databind but does not expose it in a way that makes it exploitable, reducing real-world risk in that deployment context.
  • ·OpenShift Container Platform elasticsearch plugins ship the vulnerable component but do not perform the unsafe operations required for exploitation.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.