imPC@ndo IT

Tracker / CVE-2019-14892

CVE-2019-14892

Critical 9.8

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.

Affected products and versions

apache geode
fasterxml jackson-databind · 2.0.0 → 2.6.7.3
fasterxml jackson-databind · 2.7.0 → 2.8.11.5
fasterxml jackson-databind · 2.9.0 → 2.9.10
redhat decision_manager
redhat jboss_data_grid
redhat jboss_enterprise_application_platform
redhat jboss_fuse
redhat openshift_container_platform
redhat process_automation

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References