VDB
BDU%3A2019-04778
BDU%3A2019-04778
PUBLISHED
CVSS 7.5 HIGH
Уязвимость реализации механизма полиморфной типизации данных библиотеки jackson-databind, позволяющая нарушителю выполнить вредоносную нагрузку
Risk Scores
CVSS 2.0
7.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Oracle Corp., Red Hat Inc., Fedora Project, FasterXML, LLC, Apache Software Foundation, АО «Концерн ВНИИНС» | Debian GNU/Linux, JD Edwards EnterpriseOne Tools, Oracle Retail Customer Management and Segmentation Foundation, Red Hat Enterprise Linux, Fedora, Jboss Fuse, Jboss BRMS, Retail Customer Management and Segmentation Foundation, Retail Xstore Point of Service, OpenShift Application Runtimes, JBoss Enterprise Application Platform, Jackson-databind, JBoss Data Grid, Red Hat Single Sign-On, Red Hat Process Automation Manager, JBoss Enterprise Application Platform Continuous Delivery, Drill, OpenShift Container Platform, Red Hat Descision Manager, JD Edwards EnterpriseOne Orchestrator, JBoss A-MQ Streaming, Geode, Siebel UI Framework, Communications Billing and Revenue Management, Oracle Retail Merchandising System, Oracle Retail Sales Audit, Siebel Engineering - Installer & Deployment, ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Dec 22, 2019 CVE Published
- Nov 21, 2023 CVE Updated
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2019:3901 url
- https://github.com/FasterXML/jackson-databind/issues/2478 url
- https://issues.apache.org/jira/browse/GEODE-7255 url
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E url
- https://lists.apache.org/thread.html/7782a937c9259a58337ee36b2961f00e2d744feafc13084e176d0df5@%3Cissues.geode.apache.org%3E url
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E url
- https://lists.apache.org/thread.html/b2e23c94f9dfef53e04c492e5d02e5c75201734be7adc73a49ef2370@%3Cissues.geode.apache.org%3E url
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E url
- https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/ url
- https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 url
- https://seclists.org/bugtraq/2019/Oct/6 url
- https://security.netapp.com/advisory/ntap-20191017-0006/ url
- https://www.debian.org/security/2019/dsa-4542 url
- https://www.oracle.com/security-alerts/cpujul2020.html url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url
- https://access.redhat.com/security/cve/CVE-2019-16942 advisory
- https://lists.apache.org/thread.html/a430dbc9be874c41314cc69e697384567a9a24025e819d9485547954@%3Cissues.geode.apache.org%3E advisory
- https://www.oracle.com/security-alerts/cpujan2020.html advisory