Vulnerability Description
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fasterxml | Jackson-Databind | >= 2.0.0, < 2.6.7.3 |
| Debian | Debian Linux | 8.0 |
| Redhat | Enterprise Linux | 7.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2019:1820Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2720Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2858Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2935Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2936Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2937Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2938Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2998Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3149Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3200Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3292Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3297Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3901Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4352Third Party Advisory
- https://blog.doyensec.com/2019/07/22/jackson-gadgets.htmlThird Party Advisory
FAQ
What is CVE-2019-12384?
CVE-2019-12384 is a vulnerability with a CVSS score of 5.9 (MEDIUM). FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on th...
How severe is CVE-2019-12384?
CVE-2019-12384 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12384?
Check the references section above for vendor advisories and patch information. Affected products include: Fasterxml Jackson-Databind, Debian Debian Linux, Redhat Enterprise Linux.