External risk intelligence

Jackson Databind Default Typing Remote Code Execution via Ehcache

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2019-14379

This vulnerability exists in jackson-databind, a widely used library for processing data in web applications and APIs. Because it is a core dependency for many internet-facing web services, enterprise applications, and middleware platforms, it is frequently exposed in deployments that handle external traffic or remote API requests.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in a widely used data processing library could allow unauthorized remote code execution. This issue arises from how certain configurations handle default typing, particularly when integrated with specific caching mechanisms.

  • Library flaw allows remote code execution.
  • Widely used, impacting many applications.
  • Assess exposure and relevance.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted data to a system that uses a vulnerable version of the jackson-databind library with ehcache integration. This could occur over a network without requiring authentication or user interaction, potentially leading to the execution of arbitrary code on the affected system.

  • No authentication or user interaction required.
  • Triggered by processing malicious data.
  • Leads to remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on systems using affected versions of the jackson-databind library when ehcache is also in use. This could impact the confidentiality, integrity, and availability of the system and any data it processes.

  • System data and service behavior could be affected.
  • Remote code execution could occur.
  • Compromise of system integrity and confidentiality.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determining the exact ownership requires understanding your specific deployment. Generally, application owners are responsible for the libraries their code uses, while platform or infrastructure teams manage the underlying systems and middleware where these libraries reside. The first practical step is to locate all instances of the affected technology, assess their exposure and criticality, and then identify the accountable owner for remediation planning.

  • Identify application or platform owners.
  • Verify asset reachability and criticality.
  • Coordinate remediation or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is jackson-databind?

Jackson-databind is a popular Java library that developers use to process and convert data, often translating between JSON and objects within applications. Because it is a foundational component, it is embedded in a vast array of enterprise platforms, middleware, and software products to handle data serialization tasks seamlessly.

What is the vulnerability in CVE-2019-14379?

This CVE involves a weakness classified as CWE-1321, which relates to how the library performs 'default typing.' In affected versions, the library can be tricked into creating unexpected objects when it encounters specific data patterns. When paired with the ehcache library, this flaw allows an unauthorized party to execute arbitrary code on the host system.

How does an attacker trigger this bug?

An attacker triggers this by sending maliciously crafted data to an application that processes it using a vulnerable version of jackson-databind. Crucially, the vulnerability specifically requires the ehcache library to be active and configured in a way that includes the problematic transaction manager. If ehcache is not present or not used for this specific function, this particular exploit path is not triggered.

Do I need to worry about this vulnerability?

Yes, if your systems run software that relies on vulnerable versions of jackson-databind. Halo Surface Signal notes that because this library is a core dependency for many internet-facing web services and APIs, it is often exposed to external traffic, making it a priority to identify and address in environments that accept remote requests.

What should I do to respond to CVE-2019-14379?

First, identify if any of your applications or infrastructure platforms include the affected versions of jackson-databind. Check with your software vendors for updates or patches, as this library is often updated as a bundled component. Since library management typically falls to application owners, coordinate with your development teams to upgrade to a version where this default typing behavior is restricted.

References