Description
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0440 | A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code. |
Github GHSA |
GHSA-qmqc-x3r4-6v39 | Polymorphic deserialization of malicious object in jackson-databind |
References
History
No history.
Subscriptions
Fasterxml
Subscribe
Jackson-databind
Subscribe
Netapp
Subscribe
Oncommand Api Services
Subscribe
Steelstore Cloud Integrated Storage
Subscribe
Oracle
Subscribe
Goldengate Stream Analytics
Subscribe
Redhat
Subscribe
Jboss Data Grid
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Application Platform Cd
Subscribe
Jboss Enterprise Bpms Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Fuse
Subscribe
Jboss Single Sign On
Subscribe
Openshift Application Runtimes
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T00:26:39.152Z
Reserved: 2019-08-10T00:00:00.000Z
Link: CVE-2019-14893
No data.
Status : Modified
Published: 2020-03-02T21:15:17.520
Modified: 2024-11-21T04:27:37.670
Link: CVE-2019-14893
OpenCVE Enrichment
No data.
EUVD
Github GHSA