PT-2019-3790 · Qos.Ch+3 · Logback+3

Published

2019-07-30

·

Updated

2025-09-29

·

CVE-2019-14439

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions jackson-databind versions 2.x before 2.9.9.2 jackson-databind versions 2.8.x before 2.8.11.4 jackson-databind versions 2.7.x before 2.7.9.6 jackson-databind versions 2.6.x before 2.6.7.3
Description The issue is related to a Polymorphic Typing problem in the jackson-databind library, which can occur when Default Typing is enabled for an externally exposed JSON endpoint and the logback jar is in the classpath. This can allow a remote attacker to gain unauthorized access to protected information by exploiting the vulnerability, potentially leading to the recovery of untrusted data structures in memory.
Recommendations For jackson-databind versions 2.x before 2.9.9.2, update to version 2.9.9.2 or later. For jackson-databind versions 2.8.x before 2.8.11.4, update to version 2.8.11.4 or later. For jackson-databind versions 2.7.x before 2.7.9.6, update to version 2.7.9.6 or later. For jackson-databind versions 2.6.x before 2.6.7.3, update to version 2.6.7.3 or later. As a temporary workaround, consider disabling Default Typing for externally exposed JSON endpoints until a patch is available. Restrict access to the logback jar in the classpath to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2020-3030
BDU:2019-04086
CVE-2019-14439
DLA-1879-1
DSA-4542-1
GHSA-GWP4-HFV6-P7HW
MGASA-2021-0153
OPENSUSE-SU-2024:10868-1
USN-4813-1

Affected Products

Alt Linux
Ubuntu
Jackson-Databind
Logback