Tracker / CVE-2019-14892
CVE-2019-14892
Critical 9.8
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
Affected products and versions
| apache | geode |
|---|---|
| fasterxml | jackson-databind · 2.0.0 → 2.6.7.3 |
| fasterxml | jackson-databind · 2.7.0 → 2.8.11.5 |
| fasterxml | jackson-databind · 2.9.0 → 2.9.10 |
| redhat | decision_manager |
| redhat | jboss_data_grid |
| redhat | jboss_enterprise_application_platform |
| redhat | jboss_fuse |
| redhat | openshift_container_platform |
| redhat | process_automation |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.