Логотип exploitDog
bind:CVE-2019-12814
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-12814

Количество 6

Количество 6

ubuntu логотип

CVE-2019-12814

больше 6 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

CVSS3: 5.9
EPSS: Средний
redhat логотип

CVE-2019-12814

больше 6 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2019-12814

больше 6 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

CVSS3: 5.9
EPSS: Средний
debian логотип

CVE-2019-12814

больше 6 лет назад

A Polymorphic Typing issue was discovered in FasterXML jackson-databin ...

CVSS3: 5.9
EPSS: Средний
github логотип

GHSA-cmfg-87vq-g5g4

больше 6 лет назад

Deserialization of untrusted data in FasterXML jackson-databind

CVSS3: 5.9
EPSS: Средний
fstec логотип

BDU:2019-04251

больше 6 лет назад

Уязвимость библиотеки Jackson-databind, связанная с отсутствием защиты служебных данных, позволяющая нарушителю читать произвольные файлы на сервере

CVSS3: 5.9
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-12814

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

CVSS3: 5.9
18%
Средний
больше 6 лет назад
redhat логотип
CVE-2019-12814

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

CVSS3: 7.5
18%
Средний
больше 6 лет назад
nvd логотип
CVE-2019-12814

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

CVSS3: 5.9
18%
Средний
больше 6 лет назад
debian логотип
CVE-2019-12814

A Polymorphic Typing issue was discovered in FasterXML jackson-databin ...

CVSS3: 5.9
18%
Средний
больше 6 лет назад
github логотип
GHSA-cmfg-87vq-g5g4

Deserialization of untrusted data in FasterXML jackson-databind

CVSS3: 5.9
18%
Средний
больше 6 лет назад
fstec логотип
BDU:2019-04251

Уязвимость библиотеки Jackson-databind, связанная с отсутствием защиты служебных данных, позволяющая нарушителю читать произвольные файлы на сервере

CVSS3: 5.9
18%
Средний
больше 6 лет назад

Уязвимостей на страницу