CVE detail
CVE-2019-17531 — CVE-2019-17531
Published 2019-10-12 · Modified 2026-06-17 · Vendor fasterxml · Product jackson-databind · Source nvd
CRITICAL
severity
CVSS-derived band
0.0537
EPSS probability
exploitation probability, 30d
92.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References