A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Drill
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Fasterxml
Subscribe
|
Jackson-databind
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Oracle
Subscribe
|
Banking Platform
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Instant Messaging Server
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Global Lifecycle Management Opatch
Subscribe
Goldengate Stream Analytics
Subscribe
Jd Edwards Enterpriseone Orchestrator
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Primavera Gateway
Subscribe
Retail Customer Management And Segmentation Foundation
Subscribe
Retail Xstore Point Of Service
Subscribe
Siebel Engineering - Installer \& Deployment
Subscribe
Siebel Ui Framework
Subscribe
|
|
Redhat
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1879-1 | jackson-databind security update |
Debian DSA |
DSA-4542-1 | jackson-databind security update |
EUVD |
EUVD-2019-0634 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath. |
Github GHSA |
GHSA-gwp4-hfv6-p7hw | Deserialization of untrusted data in FasterXML jackson-databind |
Ubuntu USN |
USN-4813-1 | Jackson Databind vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T00:19:41.289Z
Reserved: 2019-07-30T00:00:00
Link: CVE-2019-14439
No data.
Status : Modified
Published: 2019-07-30T11:15:11.123
Modified: 2024-11-21T04:26:44.957
Link: CVE-2019-14439
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN