CVE-2019-16942 — Deserialization of Untrusted Data in Jackson-databind
Severity
9.8CRITICALNVD
EPSS
0.4%
top 38.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 1
Latest updateMar 15
Description
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages23 packages
Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 30, 31
Patches
🔴Vulnerability Details
6CVEList▶
CVE-2019-16942: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2↗2019-10-01