peter bassill · operator
$ cve CVE-2019-14893 JSON

CVE-2019-14893

9.8
CRITICAL · CVSS 3.1 · EPSS 4.1% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.09% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploitnone known
Published2020-03-02
Last modified2026-10-08

Affected (4)

VendorProduct
fasterxmljackson-databind
netapponcommand api services
netappsteelstore cloud integrated storage
oraclegoldengate stream analytics

References

→ the Explorer  ·  watch your stack  ·  NVD