Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-12814

Опубликовано: 19 июн. 2019
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 4.3
CVSS3: 5.9

Описание

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

released

2.9.8-3
disco

ignored

end of life
eoan

released

2.9.8-3
esm-apps-legacy/xenial

released

2.4.2-3ubuntu0.1~esm2
esm-apps/bionic

needed

esm-apps/focal

released

2.9.8-3
esm-apps/jammy

released

2.9.8-3
esm-apps/noble

released

2.9.8-3

Показывать по

EPSS

Процентиль: 96%
0.10951
Средний

4.3 Medium

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 7 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

CVSS3: 5.9
nvd
около 7 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

CVSS3: 5.9
debian
около 7 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databin ...

CVSS3: 5.9
github
около 7 лет назад

Deserialization of untrusted data in FasterXML jackson-databind

CVSS3: 5.9
fstec
около 7 лет назад

Уязвимость библиотеки Jackson-databind, связанная с отсутствием защиты служебных данных, позволяющая нарушителю читать произвольные файлы на сервере

EPSS

Процентиль: 96%
0.10951
Средний

4.3 Medium

CVSS2

5.9 Medium

CVSS3