CVE-2019-10202

Aliases:GHSA-c27h-mcmw-48hvCGA-2f4p-55wg-v3hjCGA-2mfc-48q4-9cxxCGA-46h9-49ww-fgmvCGA-4828-wq63-p3jqCGA-cphh-6r2h-63v6CGA-4x8g-8x63-7fpxCGA-54w8-j76j-rq7jCGA-73jp-mfv5-36rrCGA-9fpg-5p87-36m9CGA-c976-5gw6-qprmCGA-cmcg-rc6m-fhw6CGA-ghjh-559x-r33cCGA-v4q9-4hg8-r9xpCGA-vw6x-w6mq-g532CGA-x9hr-g39x-62fvCGA-xg5v-g32m-5w33
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 01 Oct 2019, 14:22
Last modified:04 Aug 2024, 22:17

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
5.17% LOW
5% probability -2.07%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Oct 2019, 14:22
Published
Vulnerability first disclosed
04 Aug 2024, 22:17
Last Modified
Vulnerability information updated

Description

A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v3.0HIGHScore: 8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 5.17% Percentile: 92%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • chainguardhadoop-fips-3.3.6

    < 3.3.6-r15

  • chainguardspark-3.5-scala-2.12

    all

  • chainguardspark-3.5-scala-2.13

    all

  • chainguardspark-4.0-scala-2.13

    all

  • chainguardspark-fips-3.5-scala-2.12

    all

  • chainguardspark-fips-3.5-scala-2.13

    all

  • chainguardtez

    all

  • wolfispark-4.0-scala-2.13

    all

  • wolfitez

    all

  • org.codehaus.jacksonjackson-mapper-asl

    ≤ 1.9.13

  • redhatcodehaus

    Codehaus 1.9.x

  • redhatjboss_enterprise_application_platform

    7.2.0

References (18)