Back

MEDIUM

jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution

Published Jun 24, 2019

Description

FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.

Affected products

Remediation

Red Hat statement

Red Hat OpenStack's OpenDaylight does not use logback in any supported configuration. Therefore, the prerequisites for this vulnerability are not present and OpenDaylight is not affected. This vulnerability relies on logback-core (ch.qos.logback.core) being present in the application's ClassPath. Logback-core is not packaged as an RPM for Red Hat Enterprise Linux or Red Hat Software Collections. Applications using jackson-databind that do not also use logback-core are not impacted by this vulnerability. This issue affects the versions of jackson-databind bundled with candlepin as shipped with Red Hat Satellite 6.x. However the affected code is NOT used at this time.

Red Hat mitigation

The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`

References (72)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 24, 2019
Updated Aug 4, 2024
Reserved May 27, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 21, 2019
ENISA EUVD
Assigner mitre
Published Jun 24, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-0599 GHSA-MPH4-VHRX-MV67