External risk intelligence

FasterXML Jackson Databind Polymorphic Typing Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2019-17267

This CVE affects jackson-databind, a widely used library for processing JSON data in Java applications. Because it is frequently embedded in internet-facing web applications, APIs, and edge services that accept and process untrusted user-supplied JSON input, the vulnerable surface is commonly exposed to the public internet in many real-world deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects the jackson-databind library, which is commonly used in Java applications for handling data. Exploitation could allow attackers to compromise systems by sending specially crafted data. The primary concern is to confirm if this library is in use and exposed to untrusted input.

  • A library flaw allows potential system compromise.
  • Widely used software means broad exposure risk.
  • Confirm usage and external exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted data over the network to a vulnerable application. This data would target the jackson-databind library, specifically its handling of polymorphic typing related to Ehcache. Successful exploitation could allow an attacker to execute arbitrary code or disrupt the application's services.

  • No authentication or user interaction required.
  • Triggered by processing malicious data.
  • Leads to remote code execution or denial of service.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to execute arbitrary code when a vulnerable application processes maliciously crafted data. This could impact system integrity and confidentiality by enabling unauthorized actions or data access.

  • System data and service behavior.
  • Via deserialization of untrusted input.
  • Potential for unauthorized code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability, impacting `jackson-databind`, is likely to be owned by application teams and platform teams responsible for Java-based services and their underlying infrastructure. The immediate first step is to identify all instances of the affected library, determine their exposure and business criticality, and then coordinate remediation efforts.

  • Identify application owners and impacted services.
  • Verify exposure and business criticality.
  • Plan remediation in consultation with vendors.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is jackson-databind?

Jackson-databind is a popular Java library used by developers to convert data between Java objects and formats like JSON. It is a fundamental component found in many enterprise software platforms, including products from NetApp, Red Hat, and Oracle, where it facilitates efficient data processing and communication between different parts of a system.

What is the vulnerability in CVE-2019-17267?

This CVE involves a weakness classified as CWE-502, or Deserialization of Untrusted Data. Specifically, it relates to how the library handles polymorphic typing. When the library improperly processes certain data, it can be tricked into performing unauthorized actions, potentially allowing an attacker to run arbitrary code on the affected system.

How is this vulnerability triggered?

The flaw is triggered when a vulnerable application receives and processes malicious, specially crafted JSON input that exploits the library's polymorphic typing feature. It does not require the attacker to have an account or interact with the system in any other way. Processing safe or trusted data does not trigger this issue.

Is my system at risk?

Halo Surface Signal indicates that because jackson-databind is frequently embedded in internet-facing web applications and APIs, there is a high likelihood of public exposure. You should be concerned if your Java applications accept and process untrusted user-supplied JSON input, as this increases the potential for external exploitation.

What should I do to address this?

The first step is to perform an inventory of your applications to identify which services are running vulnerable versions of jackson-databind. Once identified, prioritize these services based on their business criticality and exposure to the internet, and coordinate with your platform or application teams to apply the necessary software updates.

References