CVE-2019-14893
Last modified
CVE-2019-14893 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code.. EPSS estimates a 3.96% chance of exploitation in the next 30 days.
Description
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fasterxml | Jackson-Databind | >= 2.8.0, < 2.8.11.5 |
| Fasterxml | Jackson-Databind | >= 2.9.0, < 2.9.10 |
| Netapp | Oncommand Api Services | All versions |
| Netapp | Steelstore Cloud Integrated Storage | All versions |
| Oracle | Goldengate Stream Analytics | < 19.1.0.0.1 |
References
- https://access.redhat.com/errata/RHSA-2020:0729Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14893Issue Tracking, Patch, Third Party Advisory
- https://github.com/FasterXML/jackson-databind/issues/2469Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200327-0006/Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0729Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14893Issue Tracking, Patch, Third Party Advisory
- https://github.com/FasterXML/jackson-databind/issues/2469Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200327-0006/Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-14893?
How severe is CVE-2019-14893?
How do I fix CVE-2019-14893?
Are you affected by CVE-2019-14893?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
