Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-12814

Опубликовано: 04 июн. 2019
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

A new polymorphic typing flaw was discovered in FasterXML jackson-databind, versions 2.x through 2.9.9. With default typing enabled, an attacker can send a specifically crafted JSON message to the server that allows them to read arbitrary local files.

Отчет

  • Red Hat Satellite 6 does not include the jdom or jdom2 packages, thus it is not affected by this vulnerability.
  • Red Hat OpenStack's OpenDaylight does not include the jdom or jdom2 packages, thus it is not affected by this vulnerability.

Меры по смягчению последствий

This vulnerability relies on jdom (org.jdom) or jdom2 (org.jdom2) being present in the application's ClassPath. Applications using jackson-databind that do not also use jdom or jdom2 are not impacted by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6jackson-databindWill not fix
Red Hat JBoss A-MQ 6jackson-databindAffected
Red Hat JBoss Fuse 6jackson-databindAffected
Red Hat Mobile Application Platform 4jackson-databindNot affected
Red Hat OpenShift Application Runtimesjackson-databindNot affected
Red Hat OpenShift Container Platform 3.10elasticsearch-cloud-kubernetesAffected
Red Hat OpenShift Container Platform 3.10openshift-elasticsearch-pluginAffected
Red Hat OpenShift Container Platform 3.6elasticsearch-cloud-kubernetesOut of support scope
Red Hat OpenShift Container Platform 3.6openshift-elasticsearch-pluginOut of support scope
Red Hat OpenShift Container Platform 3.7elasticsearch-cloud-kubernetesOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-502->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1725795jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server via crafted JSON message.

EPSS

Процентиль: 95%
0.18339
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 6 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

CVSS3: 5.9
nvd
больше 6 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

CVSS3: 5.9
debian
больше 6 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databin ...

CVSS3: 5.9
github
больше 6 лет назад

Deserialization of untrusted data in FasterXML jackson-databind

CVSS3: 5.9
fstec
больше 6 лет назад

Уязвимость библиотеки Jackson-databind, связанная с отсутствием защиты служебных данных, позволяющая нарушителю читать произвольные файлы на сервере

EPSS

Процентиль: 95%
0.18339
Средний

7.5 High

CVSS3