Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-12384
HistoryJun 24, 2019 - 4:15 p.m.

Deserialization of untrusted data

2019-06-2416:15:00
PRIOn knowledge base
www.prio-n.com
8

7.8 High

AI Score

Confidence

High

0.533 Medium

EPSS

Percentile

97.6%

FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.

References