CVE Database
/

CVE-2019-17531

Back to search

CVE-2019-17531

Published: Oct 12, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2019:4192
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0164
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0159
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0160
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0161
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0445
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now