A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.
{
"versions": [
{
"introduced": "2.0.0"
},
{
"fixed": "2.6.7.3"
},
{
"introduced": "2.8.0"
},
{
"fixed": "2.8.11.5"
},
{
"introduced": "2.9.0"
},
{
"fixed": "2.9.10.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.9.0"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "30"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "31"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3"
}
]
},
{
"events": [
{
"introduced": "7.3"
}
]
},
{
"events": [
{
"introduced": "7.3"
}
]
},
{
"events": [
{
"introduced": "9.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.5.0.23.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.0.0.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.0.2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.0.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.2.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "18c"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19c"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "13.9.4.2.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.1.0.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2"
}
]
},
{
"events": [
{
"introduced": "17.12.0"
},
{
"last_affected": "17.12.6"
}
]
},
{
"events": [
{
"introduced": "18.8.0"
},
{
"last_affected": "18.8.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.12.0"
}
]
},
{
"events": [
{
"introduced": "17.7"
},
{
"last_affected": "17.12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "18.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.20.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "20.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "20.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.4.0"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-16942.json"