FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.
{
"versions": [
{
"introduced": "2.0.0"
},
{
"fixed": "2.6.7.3"
},
{
"introduced": "2.7.0"
},
{
"fixed": "2.7.9.6"
},
{
"introduced": "2.8.0"
},
{
"fixed": "2.8.11.4"
},
{
"introduced": "2.9.0"
},
{
"fixed": "2.9.9.1"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.7"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-12384.json"