CVE-2019-14893
Summary
| CVE | CVE-2019-14893 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-02 21:15:00 UTC |
| Updated | 2023-11-07 03:05:00 UTC |
| Description | A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Pony Mail! |
|
lists.apache.org |
|
| Block one more gadget type (xalan2) · Issue #2469 · FasterXML/jackson-databind · GitHub |
MISC |
github.com |
Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Oracle Critical Patch Update Advisory - July 2020 |
MISC |
www.oracle.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| CVE-2019-14893 FasterXML jackson-databind Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Oracle Critical Patch Update Advisory - October 2020 |
MISC |
www.oracle.com |
Third Party Advisory |
| 1758182 – (CVE-2019-14893) CVE-2019-14893 jackson-databind: Serialization gadgets in classes of the xalan package |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 373312 IBM Sterling B2B Integrator Multiple security Vulnerabilities
- 375626 IBM Cognos Analytics Multiple Vulnerabilities (6451705)
- 982937 Java (maven) Security Update for com.fasterxml.jackson.core:jackson-databind (GHSA-qmqc-x3r4-6v39)