Severity
9.8CRITICAL
EPSS
1.2%
top 21.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 12
Latest updateJul 15

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages21 packages

NVDfasterxml/jackson-databind2.0.02.6.7.3+2
Debianjackson-databind< 2.10.1-1+3
NVDoracle/primavera_gateway17.717.12.6+4

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

5
OSV
jackson-databind vulnerabilities2021-03-15
OSV
jackson-databind polymorphic typing issue2019-11-13
GHSA
jackson-databind polymorphic typing issue2019-11-13
CVEList
CVE-2019-17531: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 22019-10-12
OSV
CVE-2019-17531: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 22019-10-12

📋Vendor Advisories

6
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (jackson-databind) — CVE-2019-175312023-07-15
Ubuntu
Jackson Databind vulnerabilities2021-03-15
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Build Request (jackson-databind) — CVE-2019-175312020-10-15
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (jackson-databind) — CVE-2019-175312020-07-15
Red Hat
jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.*2019-10-12

💬Community

2
Bugzilla
CVE-2019-17531 jackson-databind: polymorphic typing issue when enabling default typing for an externally exposed JSON endpoint and having apache-log4j-extra in the classpath leads to code execution [f2019-11-21
Bugzilla
CVE-2019-17531 jackson-databind: Serialization gadgets in org.apache.log4j.receivers.db.*2019-11-21