Lucene search

K
redhatcveRedhat.comRH:CVE-2019-20330
HistoryMay 14, 2022 - 11:39 a.m.

CVE-2019-20330

2022-05-1411:39:39
redhat.com
access.redhat.com
38
cve-2019-20330
deserialization
enabledefaulttyping
jsontypeinfo
exploit
mitigation

EPSS

0.006

Percentile

79.0%

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

Mitigation

The following conditions are needed for an exploit, we recommend avoiding all if possible:

  • Deserialization from sources you do not control
  • enableDefaultTyping()
  • @JsonTypeInfo using id.CLASSorid.MINIMAL_CLASS`