CVE-2019-14439
HIGHFasterXML jackson-databind <2.9.9.2 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2019-14439. PoCs published by jas502n, dawetmaster, andikahilmy.
AI-analyzed exploit summary The repository contains only a minimal README with a CVE title and no functional exploit code or technical details. It lacks any meaningful content to demonstrate or analyze the vulnerability.
Description
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
Exploits (3)
The repository contains only a minimal README with a CVE title and no functional exploit code or technical details. It lacks any meaningful content to demonstrate or analyze the vulnerability.
This repository contains a vulnerable version of Jackson Databind (2.9.0) that is susceptible to CVE-2019-14439, a deserialization vulnerability. The included source code and build configuration allow for testing and exploitation of the flaw.
This repository contains a vulnerable version of Jackson Databind (2.9.0) that demonstrates CVE-2019-14439, a deserialization vulnerability allowing arbitrary code execution. The included source code and build configuration enable testing of the exploit in a controlled environment.
References (29)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N