Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-12814

Опубликовано: 19 июн. 2019
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 4.3
CVSS3: 5.9

Описание

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

released

2.9.8-3
disco

ignored

end of life
eoan

released

2.9.8-3
esm-apps/bionic

needed

esm-apps/focal

released

2.9.8-3
esm-apps/jammy

released

2.9.8-3
esm-apps/noble

released

2.9.8-3
esm-apps/xenial

released

2.4.2-3ubuntu0.1~esm2

Показывать по

EPSS

Процентиль: 95%
0.18339
Средний

4.3 Medium

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 6 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

CVSS3: 5.9
nvd
больше 6 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

CVSS3: 5.9
debian
больше 6 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databin ...

CVSS3: 5.9
github
больше 6 лет назад

Deserialization of untrusted data in FasterXML jackson-databind

CVSS3: 5.9
fstec
больше 6 лет назад

Уязвимость библиотеки Jackson-databind, связанная с отсутствием защиты служебных данных, позволяющая нарушителю читать произвольные файлы на сервере

EPSS

Процентиль: 95%
0.18339
Средний

4.3 Medium

CVSS2

5.9 Medium

CVSS3