CVE Published: 02/03/2020 |
CVE Updated: 05/08/2024 |
CVE Year: 2019 Source: redhat |
Vendor: Red Hat |
Product: jackson-databind Status : PUBLISHED
CVE-2019-14892 Description
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.