Lucene search

K
osvGoogleOSV:CVE-2019-14892
HistoryMar 02, 2020 - 5:15 p.m.

CVE-2019-14892

2020-03-0217:15:17
Google
osv.dev
10

AI Score

7.1

Confidence

Low

EPSS

0.004

Percentile

73.4%

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.

AI Score

7.1

Confidence

Low

EPSS

0.004

Percentile

73.4%