CVE-2019-14892 - CVE House
Back to Database
Status published High CVE-2019-14892

A flaw was discovered in jackson-databind in versions before 2.9.10,...

Vulnerability Description

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-14892

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

jackson-databind
Vulnerable Versions:
Versions before 2.9.10, Versions before 2.8.11.5, Versions before 2.6.7.3

Timeline

Official Publish: March 2nd, 2020
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)