PT-2019-4183 · Jackson+6 · Jackson-Databind+6
Publicado
2017-11-01
·
Atualizado
2025-01-28
·
CVE-2019-16943
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
jackson-databind versions 2.0.0 through 2.9.10
jackson-databind versions prior to 2.9.10.1
jackson-databind versions prior to 2.8.11.5
jackson-databind versions prior to 2.6.7.3
Description
A Polymorphic Typing issue was discovered in the jackson-databind library. The issue is related to the mishandling of input data by the
com.p6spy.engine.spy.P6DataSource class. When Default Typing is enabled for an externally exposed JSON endpoint and the service has the p6spy jar in the classpath, an attacker can exploit this issue to execute a malicious payload by accessing an RMI service endpoint.Recommendations
For jackson-databind versions 2.0.0 through 2.9.10, update to version 2.9.10.1 or later.
For jackson-databind versions prior to 2.8.11.5, update to version 2.8.11.5 or later.
For jackson-databind versions prior to 2.6.7.3, update to version 2.6.7.3 or later.
As a temporary workaround, consider disabling the
com.p6spy.engine.spy.P6DataSource class until a patch is available.
Restrict access to the RMI service endpoint to minimize the risk of exploitation.Exploit
Correção
RCE
Information Disclosure
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Ubuntu
Jackson-Databind