A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Jackson-databind | Fasterxml | 2.0.0 (including) | 2.6.7.3 (excluding) |
| Jackson-databind | Fasterxml | 2.7.0 (including) | 2.7.9.6 (excluding) |
| Jackson-databind | Fasterxml | 2.8.0 (including) | 2.8.11.4 (excluding) |
| Jackson-databind | Fasterxml | 2.9.0 (including) | 2.9.9.2 (excluding) |
| Red Hat AMQ Streams 1 | RedHat | * | |
| Red Hat Decision Manager 7 | RedHat | jackson-databind | * |
| Red Hat Enterprise Linux 8 | RedHat | pki-core:10.6-8010020190912123424.8ba0ffbe | * |
| Red Hat Enterprise Linux 8 | RedHat | pki-deps:10.6-8010020190731203900.cdc1202b | * |
| Red Hat Fuse 6.3 | RedHat | * | |
| Red Hat Fuse 7.6.0 | RedHat | jackson-databind | * |
| Red Hat JBoss EAP 7.2 | RedHat | jackson-databind | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-activemq-artemis-0:2.9.0-1.redhat_00005.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-glassfish-jsf-0:2.3.5-4.SP3_redhat_00002.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-hal-console-0:3.0.16-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-hibernate-0:5.3.11-2.SP1_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-infinispan-0:9.3.7-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-ironjacamar-0:1.4.17-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jackson-annotations-0:2.9.9-1.redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jackson-core-0:2.9.9-1.redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jackson-databind-0:2.9.9.3-1.redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jackson-jaxrs-providers-0:2.9.9-2.redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jackson-modules-base-0:2.9.9-1.redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jackson-modules-java8-0:2.9.9-1.redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jboss-ejb-client-0:4.0.23-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jboss-jaxrs-api_2.1_spec-0:1.0.3-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jboss-logging-0:3.3.3-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jboss-logmanager-0:2.1.14-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jboss-marshalling-0:2.0.9-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jboss-msc-0:1.4.8-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jboss-remoting-0:5.0.14-1.SP1_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jboss-server-migration-0:1.3.1-4.Final_redhat_00004.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jboss-xnio-base-0:3.7.3-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-jgroups-0:4.0.20-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-narayana-0:5.9.6-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-netty-0:4.1.34-2.Final_redhat_00002.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-picketbox-0:5.0.3-5.Final_redhat_00004.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-picketlink-bindings-0:2.5.5-20.SP12_redhat_00007.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-picketlink-federation-0:2.5.5-20.SP12_redhat_00007.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-undertow-0:2.0.25-1.SP1_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-weld-core-0:3.0.6-2.Final_redhat_00002.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-wildfly-0:7.2.4-1.GA_redhat_00002.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-wildfly-elytron-0:1.6.4-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-wildfly-elytron-tool-0:1.4.3-1.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | RedHat | eap7-wildfly-transaction-client-0:1.1.6-2.Final_redhat_00001.1.el6eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-activemq-artemis-0:2.9.0-1.redhat_00005.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-glassfish-jsf-0:2.3.5-4.SP3_redhat_00002.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-hal-console-0:3.0.16-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-hibernate-0:5.3.11-2.SP1_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-infinispan-0:9.3.7-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-ironjacamar-0:1.4.17-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jackson-annotations-0:2.9.9-1.redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jackson-core-0:2.9.9-1.redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jackson-databind-0:2.9.9.3-1.redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jackson-jaxrs-providers-0:2.9.9-2.redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jackson-modules-base-0:2.9.9-1.redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jackson-modules-java8-0:2.9.9-1.redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jboss-ejb-client-0:4.0.23-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jboss-jaxrs-api_2.1_spec-0:1.0.3-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jboss-logging-0:3.3.3-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jboss-logmanager-0:2.1.14-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jboss-marshalling-0:2.0.9-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jboss-msc-0:1.4.8-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jboss-remoting-0:5.0.14-1.SP1_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jboss-server-migration-0:1.3.1-4.Final_redhat_00004.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jboss-xnio-base-0:3.7.3-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-jgroups-0:4.0.20-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-narayana-0:5.9.6-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-netty-0:4.1.34-2.Final_redhat_00002.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-picketbox-0:5.0.3-5.Final_redhat_00004.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-picketlink-bindings-0:2.5.5-20.SP12_redhat_00007.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-picketlink-federation-0:2.5.5-20.SP12_redhat_00007.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-undertow-0:2.0.25-1.SP1_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-weld-core-0:3.0.6-2.Final_redhat_00002.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-wildfly-0:7.2.4-1.GA_redhat_00002.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-wildfly-elytron-0:1.6.4-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-wildfly-elytron-tool-0:1.4.3-1.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7 | RedHat | eap7-wildfly-transaction-client-0:1.1.6-2.Final_redhat_00001.1.el7eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-activemq-artemis-0:2.9.0-1.redhat_00005.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-glassfish-jsf-0:2.3.5-4.SP3_redhat_00002.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-hal-console-0:3.0.16-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-hibernate-0:5.3.11-2.SP1_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-infinispan-0:9.3.7-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-ironjacamar-0:1.4.17-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jackson-annotations-0:2.9.9-1.redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jackson-core-0:2.9.9-1.redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jackson-databind-0:2.9.9.3-1.redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jackson-jaxrs-providers-0:2.9.9-2.redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jackson-modules-base-0:2.9.9-1.redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jackson-modules-java8-0:2.9.9-1.redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jboss-ejb-client-0:4.0.23-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jboss-jaxrs-api_2.1_spec-0:1.0.3-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jboss-logging-0:3.3.3-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jboss-logmanager-0:2.1.14-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jboss-marshalling-0:2.0.9-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jboss-msc-0:1.4.8-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jboss-remoting-0:5.0.14-1.SP1_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jboss-server-migration-0:1.3.1-4.Final_redhat_00004.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jboss-xnio-base-0:3.7.3-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-jgroups-0:4.0.20-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-narayana-0:5.9.6-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-netty-0:4.1.34-2.Final_redhat_00002.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-picketbox-0:5.0.3-5.Final_redhat_00004.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-picketlink-bindings-0:2.5.5-20.SP12_redhat_00007.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-picketlink-federation-0:2.5.5-20.SP12_redhat_00007.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-undertow-0:2.0.25-1.SP1_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-weld-core-0:3.0.6-2.Final_redhat_00002.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-wildfly-0:7.2.4-1.GA_redhat_00002.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-wildfly-elytron-0:1.6.4-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-wildfly-elytron-tool-0:1.4.3-1.Final_redhat_00001.1.el8eap | * |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8 | RedHat | eap7-wildfly-transaction-client-0:1.1.6-2.Final_redhat_00001.1.el8eap | * |
| Red Hat OpenShift Container Platform 3.11 | RedHat | openshift3/ose-logging-elasticsearch5:v3.11.153-2 | * |
| Red Hat OpenShift Container Platform 4.1 | RedHat | openshift4/ose-logging-elasticsearch5:v4.1.18-201909201915 | * |
| Red Hat Process Automation 7 | RedHat | jackson-databind | * |
| Red Hat Single Sign-On 7.3.4 zip | RedHat | jackson-databind | * |
| Red Hat Single Sign-On 7.3 for RHEL 6 | RedHat | rh-sso7-keycloak-0:4.8.13-1.Final_redhat_00001.1.el6sso | * |
| Red Hat Single Sign-On 7.3 for RHEL 7 | RedHat | rh-sso7-keycloak-0:4.8.13-1.Final_redhat_00001.1.el7sso | * |
| Red Hat Single Sign-On 7.3 for RHEL 7 | RedHat | rh-sso7-libunix-dbus-java-0:0.8.0-2.el7sso | * |
| Red Hat Single Sign-On 7.3 for RHEL 8 | RedHat | rh-sso7-keycloak-0:4.8.13-1.Final_redhat_00001.1.el8sso | * |
| Jackson-databind | Ubuntu | bionic | * |
| Jackson-databind | Ubuntu | cosmic | * |
| Jackson-databind | Ubuntu | devel | * |
| Jackson-databind | Ubuntu | disco | * |
| Jackson-databind | Ubuntu | eoan | * |
| Jackson-databind | Ubuntu | esm-apps/bionic | * |
| Jackson-databind | Ubuntu | esm-apps/focal | * |
| Jackson-databind | Ubuntu | esm-apps/jammy | * |
| Jackson-databind | Ubuntu | esm-apps/noble | * |
| Jackson-databind | Ubuntu | esm-apps/xenial | * |
| Jackson-databind | Ubuntu | focal | * |
| Jackson-databind | Ubuntu | groovy | * |
| Jackson-databind | Ubuntu | hirsute | * |
| Jackson-databind | Ubuntu | impish | * |
| Jackson-databind | Ubuntu | jammy | * |
| Jackson-databind | Ubuntu | kinetic | * |
| Jackson-databind | Ubuntu | lunar | * |
| Jackson-databind | Ubuntu | mantic | * |
| Jackson-databind | Ubuntu | noble | * |
| Jackson-databind | Ubuntu | oracular | * |
| Jackson-databind | Ubuntu | plucky | * |
| Jackson-databind | Ubuntu | questing | * |
| Jackson-databind | Ubuntu | trusty | * |
| Jackson-databind | Ubuntu | trusty/esm | * |
| Jackson-databind | Ubuntu | xenial | * |