Uploaded image for project: 'Optimization Framework'
  1. Optimization Framework
  2. OPTFRA-624

CMSO Security/Vulnerability CVE-2019- 12384 jackson- databind

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Medium Medium
    • None
    • El Alto Release
    • CMSO
    • None

       

      CMSO Security/Vulnerability CVE-2019- 12384 jackson- databind

       

      FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible. The jackson-databind package is vulnerable to Remote Code Execution (RCE). The validateSubType() function in the SubTy peValidator class allows untrusted Java objects, such as ch. qos.logback.core.db.DriverManagerConnectionSource, to be deserialized. A remote attacker can exploit this by uploading a malicious serialized object that will result in RCE if the application attempts to deserialize it.

       

      com. fasterxml.jackson. core jackson- databind 2.9.9 CVE-2019- 12384 Ineffective

            jf9860 jf9860
            jf9860 jf9860
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: