CVE-2019-14892

Aliases:GHSA-cf6r-3wgc-h863
Modified
Published: 02 Mar 2020, 16:28
Last modified:05 Aug 2024, 00:26

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
0.9% LOW
1% probability +0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

02 Mar 2020, 16:28
Published
Vulnerability first disclosed
05 Aug 2024, 00:26
Last Modified
Vulnerability information updated

Description

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v3.0HIGHScore: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.90% Percentile: 76%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • apachegeode

    1.12.0

  • fasterxmljackson-databind

    ≥ 2.0.0, < 2.6.7.3 | ≥ 2.7.0, < 2.8.11.5 | ≥ 2.9.0, < 2.9.10

  • com.fasterxml.jackson.corejackson-databind

    < 2.6.7.3 | ≥ 2.7.0, < 2.8.11.5 | ≥ 2.9.0, < 2.9.10

  • red hatjackson-databind

    Versions before 2.9.10 | Versions before 2.8.11.5 | Versions before 2.6.7.3

  • redhatdecision_manager

    7.0

  • redhatjboss_data_grid

    na | 7.0.0

  • redhatjboss_enterprise_application_platform

    7.0

  • redhatjboss_fuse

    7.0.0

  • redhatopenshift_container_platform

    4.3

  • redhatprocess_automation

    7.0

References (13)