Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-12086

Опубликовано: 17 мая 2019
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 5
CVSS3: 7.5

Описание

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing com.mysql.cj.jdbc.admin.MiniAdmin validation.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

released

2.9.8-2
disco

ignored

end of life
eoan

released

2.9.8-2
esm-apps/bionic

needed

esm-apps/focal

released

2.9.8-2
esm-apps/jammy

released

2.9.8-2
esm-apps/noble

released

2.9.8-2
esm-apps/xenial

released

2.4.2-3ubuntu0.1~esm2

Показывать по

РелизСтатусПримечание
bionic

not-affected

cosmic

not-affected

devel

not-affected

disco

not-affected

eoan

not-affected

esm-apps/bionic

not-affected

esm-apps/focal

not-affected

esm-apps/jammy

not-affected

esm-apps/noble

not-affected

esm-infra-legacy/trusty

DNE

Показывать по

EPSS

Процентиль: 94%
0.15745
Средний

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 6 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing com.mysql.cj.jdbc.admin.MiniAdmin validation.

CVSS3: 7.5
nvd
около 6 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing com.mysql.cj.jdbc.admin.MiniAdmin validation.

CVSS3: 7.5
debian
около 6 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databin ...

CVSS3: 7.5
github
около 6 лет назад

Information exposure in FasterXML jackson-databind

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость библиотеки Jackson-databind, связанная с отсутствием защиты служебных данных, позволяющая нарушителю прочитать произвольные файлы на сервере

EPSS

Процентиль: 94%
0.15745
Средний

5 Medium

CVSS2

7.5 High

CVSS3