External risk intelligence

FasterXML Jackson Polymorphic Typing Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2019-16943

The vulnerability exists in jackson-databind, a widely used library for processing JSON, which is a foundational component of internet-facing web applications and API services. While the vulnerability requires specific configuration and dependencies, it is inherently designed to handle untrusted input from external networks, making internet-facing exposure a common deployment pattern for applications utilizing this library.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security issue has been identified in a widely used software component, which, under specific circumstances and with certain additional software present, could allow an attacker to execute malicious code. This could impact the integrity and availability of affected services. The primary concern is to determine if your environment utilizes the affected component and if the conditions for exploitation are present.

  • A library flaw could enable code execution.
  • Understand if this library is in use.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted JSON data to an exposed endpoint. If the application uses the jackson-databind library with default typing enabled and includes the p6spy jar, the attacker can leverage a Remote Method Invocation (RMI) service to execute arbitrary code. This attack path relies on the library's mishandling of polymorphic types when processing untrusted JSON input.

  • Unauthenticated network access required.
  • Malicious JSON triggers vulnerable type handling.
  • Enables remote code execution.

Live Threat

Current exploitation, exposure, and threat context

When Default Typing is enabled for an external JSON endpoint and the `p6spy` library is present, an attacker could potentially execute malicious code by targeting an RMI service. This occurs due to how `com.p6spy.engine.spy.P6DataSource` handles certain data inputs.

  • Server-side code execution.
  • Via JSON parsing with specific setup.
  • Compromise of service integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in `jackson-databind` with `p6spy` in the classpath, when Default Typing is enabled, requires an attacker to access an RMI service endpoint to execute a malicious payload. Owners of applications using `jackson-databind` must first identify instances of this library, confirm exposure via RMI, and assess business criticality. Remediation planning should prioritize these exposed and critical systems.

  • Application owners and platform teams.
  • Confirm RMI service exposure and reachability.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is jackson-databind?

Jackson-databind is a popular Java library that developers use to convert data between Java objects and JSON, which is a standard format for sharing data across the web. It is widely embedded within many enterprise applications, including various database tools, cloud-integrated storage platforms, and financial management software, to help them communicate with external web services and APIs.

What does CVE-2019-16943 mean?

This CVE describes a weakness known as Deserialization of Untrusted Data, categorized as CWE-502. In simple terms, it occurs because the software may trust incoming JSON data too much. If configured in a specific way, the library can be tricked into executing harmful commands instead of just reading data, allowing an attacker to run unauthorized code on the system.

How does an attacker trigger this bug?

To trigger the vulnerability, an attacker needs to find a service that enables a feature called Default Typing for incoming JSON and also has the p6spy library present in its classpath. The bug does not trigger if Default Typing is disabled, nor does it affect environments that lack the specific p6spy component required to facilitate the unintended execution.

Is my system at risk?

Per Halo Surface Signal, this vulnerability is most relevant to systems with internet-facing endpoints that process JSON input. Because jackson-databind is frequently used to build APIs, any service that exposes these endpoints to the public internet should be considered a higher priority for review than internal-only services.

What should I do first to address this?

Start by identifying which of your applications use jackson-databind and whether they have 'Default Typing' enabled. You should then consult the documentation for your specific software vendor to obtain and apply the recommended security updates or patches that resolve this dependency issue.

References