Back

CRITICAL

jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource

Published Oct 1, 2019

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

Affected products

Remediation

Red Hat statement

Satellite 6 does not enable polymorphic unmarshmalling, which is a required configuration for the vulnerability to be used. We may update the jackson-databind dependency in a future release. Red Hat OpenStack Platform ships OpenDaylight, which contains the vulnerable jackson-databind. However, OpenDaylight does not expose jackson-databind in a way that would make it vulnerable, lowering the impact of the vulnerability for OpenDaylight. As such, Red Hat will not be providing a fix for OpenDaylight at this time.

Red Hat mitigation

The following conditions are needed for an exploit, we recommend avoiding all if possible * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`

References (45)

Change history (1)
  1. EUVD
    • Updated

      changed from Aug 5, 2024 to Oct 7, 2026

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Oct 1, 2019
Updated Oct 7, 2026
Reserved Sep 29, 2019

CISA Vulnrichment

Updated Oct 7, 2026

NVD

Status Modified
Modified Oct 7, 2026

Red Hat

Severity Moderate
Public date Sep 27, 2019
Bugzilla 1758191

ENISA EUVD

Assigner mitre
Published Oct 1, 2019
Updated Oct 7, 2026