← Back

CVE-2019-14439

nvd nist
Published: Jul 30, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.

Affected (45)

Show all products
1 product
Jackson Databind
1 product
Debian Linux
1 product
Fedora
1 product
Drill
1 product
13 products
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Fasterxml
From 2.0.0 to 2.6.7.3
From 2.7.0 to 2.7.9.6
From 2.8.0 to 2.8.11.4
From 2.9.0 to 2.9.9.2
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 8.0
Version 9.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 29
Version 30
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.16.0
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.0
Configuration F
34 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 2.4.0
Version 2.4.1
Version 2.5.0
Version 2.6.0
Version 2.6.1
Version 2.7.0
Version 2.7.1
Oracle
Version 8.0.0
Version 8.1
Version 8.2.1
Version 8.2
Version 10.0.1.3.0
From 8.0.2 to 8.0.8
Oracle
Before 11.2.0.3.23
From 12.2.0.1.0 to 12.2.0.1.19
From 13.9.4.0.0 to 13.9.4.2.1
Version 11.2.0.3.23
Version 13.9.4.2.1
Before 19.1.0.0.1
Version 9.2
Version 9.2
Oracle
From 17.7 to 17.12
Version 15.2
Version 16.1
Version 16.2
Version 18.8.0
Version 17.0
Oracle
Version 15.0
Version 16.0
Version 17.0
Version 18.0
Version 7.1
Up to 19.8
Up to 19.10

References (58)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.