CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2019-14892

CVSS 9.8v3.1pub. 2020-03-02upd. 2024-11-21

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Geode

    APP
    Apache
    1.12.0
  • Fasterxml Jackson Databind

    APP
    Fasterxml
    2.7.0 – 2.8.11.5 (excl.)2.9.0 – 2.9.10 (excl.)2.0.0 – 2.6.7.3 (excl.)
  • Red Hat Decision Manager

    APP
    Redhat
    7.0
  • Red Hat Jboss Data Grid

    APP
    Redhat
    7.0.0
  • Red Hat Jboss Enterprise Application Platform

    APP
    Redhat
    7.0
  • Red Hat Jboss Fuse

    APP
    Redhat
    7.0.0
  • Red Hat OpenShift Container Platform

    APP
    Redhat
    4.3
  • Red Hat Process Automation

    APP
    Redhat
    7.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEDeserialization
CWE
References

Related vulnerabilities

CVE-2020-1938CRITICAL9.8⚠ KEVPL ✓same product

Apache Tomcat AJP Connector — odczyt plików i RCE (Ghostcat)

CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓same product

RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu

CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓same product

Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE

CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓same product

Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)

CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓same product

RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework