CVE-2019-20330: Critical severity fasterxml jackson-databind vulnerability
FasterXML jackson-databind 2.x before 2.6.7.4, 2.7.x before 2.7.9.7, 2.8.x before 2.8.11.5, and 2.9.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
Other sources
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/candlepinto a version that resolves this vulnerability.Fixed in 0:2.6.16-1.el7 - Upgrade
Upgrade
redhat/foremanto a version that resolves this vulnerability.Fixed in 0:1.22.0.39-2.el7 - Upgrade
Upgrade
redhat/satelliteto a version that resolves this vulnerability.Fixed in 0:6.6.3-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-ovirtto a version that resolves this vulnerability.Fixed in 0:1.2.3-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-katelloto a version that resolves this vulnerability.Fixed in 0:3.12.0.41-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-runcibleto a version that resolves this vulnerability.Fixed in 0:2.13.0-1.el7 - Upgrade
Upgrade
redhat/candlepinto a version that resolves this vulnerability.Fixed in 0:2.9.28-1.el7 - Upgrade
Upgrade
redhat/foremanto a version that resolves this vulnerability.Fixed in 0:1.24.1.24-1.el7 - Upgrade
Upgrade
redhat/foreman-installerto a version that resolves this vulnerability.Fixed in 1:1.24.1.21-1.el7 - Upgrade
Upgrade
redhat/pulp-rpmto a version that resolves this vulnerability.Fixed in 0:2.21.0.6-1.el7 - Upgrade
Upgrade
redhat/satelliteto a version that resolves this vulnerability.Fixed in 0:6.7.2-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-fog-vsphereto a version that resolves this vulnerability.Fixed in 0:3.2.1.1-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-foreman-tasksto a version that resolves this vulnerability.Fixed in 0:0.17.5.6-1.el7 - Upgrade
Upgrade
redhat/tfm-rubygem-katelloto a version that resolves this vulnerability.Fixed in 0:3.14.0.25-1.el7 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.6.7.4 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.10.2 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.8.11.5 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.7.9.7 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.10.2 - Upgrade
Upgrade
FasterXML jackson-databind 2.xto a version that resolves this vulnerability.Fixed in 2.6.7.4 - Upgrade
Upgrade
FasterXML jackson-databind 2.xto a version that resolves this vulnerability.Fixed in 2.7.9.7 - Upgrade
Upgrade
FasterXML jackson-databind 2.xto a version that resolves this vulnerability.Fixed in 2.8.11.5 - Upgrade
Upgrade
FasterXML jackson-databind 2.xto a version that resolves this vulnerability.Fixed in 2.9.10.2 - Configuration
Avoid using @JsonTypeInfo with `using` set to `id.CLASS` or `id.MINIMAL_CLASS` when deserializing data from sources you do not control.
Jackson Databind @JsonTypeInfo using = id.CLASS / id.MINIMAL_CLASS - Configuration
Do not call enableDefaultTyping() (avoid enabling default typing) when deserializing data from sources you do not control.
Jackson Databind enableDefaultTyping() = false (do not enable) - Compensating control
Avoid deserializing from sources you do not control (ensure exploit conditions are not met), as recommended in the provided references.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-20330?
The severity of CVE-2019-20330 is considered to be unknown due to insufficient details about its impact and attack vector.
How do I fix CVE-2019-20330?
To fix CVE-2019-20330, update to the recommended versions of FasterXML jackson-databind as specified in the software's documentation.
What software is affected by CVE-2019-20330?
CVE-2019-20330 affects various versions of FasterXML jackson-databind, including 2.x before 2.6.7.4, 2.7.x before 2.7.9.7, and so on.
Is there a specific version to upgrade to for CVE-2019-20330?
Yes, you should upgrade to the specified fixed versions, such as jackson-databind 2.9.10.2 or others depending on your current version.
What are the implications of CVE-2019-20330 for my applications?
While the exact implications of CVE-2019-20330 are not well documented, it is advisable to apply patches to mitigate any risks associated with the vulnerability.