Lucene search

K
redhatcveRedhat.comRH:CVE-2019-17267
HistoryApr 06, 2020 - 4:58 a.m.

CVE-2019-17267

2020-04-0604:58:17
redhat.com
access.redhat.com
103

EPSS

0.012

Percentile

85.0%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.

Mitigation

The following conditions are needed for an exploit, we recommend avoiding all if possible

  • Deserialization from sources you do not control
  • enableDefaultTyping()
  • @JsonTypeInfo using id.CLASSorid.MINIMAL_CLASS`