External risk intelligence

Jackson Databind Polymorphic Typing Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2019-17531

The vulnerability involves FasterXML jackson-databind, a widely used library for processing JSON data in web applications and APIs. Because it specifically affects endpoints where default typing is enabled to handle incoming JSON, the vulnerable code is frequently deployed in internet-facing web services, APIs, and edge-handling components that process user-supplied input.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in a widely used Java library for processing JSON data, specifically when default typing is enabled for external data inputs and a particular logging library is present. This combination allows an attacker to potentially execute malicious code on affected systems.

  • Allows code execution via data input.
  • Leadership should remember it for data input risks.
  • Confirm relevance and exposure of data processing.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this by sending specially crafted JSON data to an externally exposed endpoint. If the service uses `jackson-databind` with default typing enabled and has `apache-log4j-extra` in its classpath, the attacker can provide a JNDI service. This allows the service to execute arbitrary code with a malicious payload, leading to a compromise of the system.

  • Attacker sends malicious JSON to an endpoint.
  • Default typing and log4j-extra are enabled.
  • Arbitrary code execution on the service.

Live Threat

Current exploitation, exposure, and threat context

When Default Typing is enabled for an externally exposed JSON endpoint and the `apache-log4j-extra` jar is present, an attacker could provide a JNDI service to execute a malicious payload. This could affect the availability and integrity of the affected service.

  • System data and service behavior may be at risk.
  • An attacker could exploit JNDI and JSON processing.
  • The service could experience unauthorized code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The fasterxml jackson-databind vulnerability, when Default Typing is enabled and the `apache-log4j-extra` jar is present, can lead to malicious payload execution. Ownership typically falls to the application or platform teams responsible for services processing external JSON inputs. The first actionable step is to identify all instances of the affected library, determine their reachability and business criticality, and then prioritize remediation based on risk.

  • Application and platform teams own remediation.
  • Verify Default Typing enabled and log4j-extra presence.
  • Plan remediation based on exposure and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the jackson-databind library?

Jackson-databind is a common Java library used to process and convert data between JSON format and Java objects. It is a foundational component for many web applications and APIs, used by major vendors like Oracle, Red Hat, and NetApp to handle incoming data requests.

What is the vulnerability in CVE-2019-17531?

This vulnerability is a Polymorphic Typing issue, classified as CWE-502: Deserialization of Untrusted Data. It occurs when the library is configured to allow polymorphic type handling, which can be manipulated to cause the application to perform unintended actions instead of just processing data.

How does an attacker trigger this bug?

The vulnerability requires specific conditions: Default Typing must be enabled on an endpoint that accepts external JSON input, and the apache-log4j-extra library must be present in the application's classpath. If these are not met—for example, if Default Typing is disabled—the attack path cannot be established.

Is my system at risk?

According to Halo Surface Signal, this risk is highly relevant for internet-facing services, APIs, and edge-handling components that process user-supplied input. If your software uses an affected version of the library and exposes these types of endpoints to the internet, it is a priority for investigation.

What should I do if I am running this technology?

First, verify whether your applications use the affected versions of jackson-databind and if they have Default Typing enabled. Identify if the apache-log4j-extra dependency is included in your environment. Consult your vendor's security updates to plan for patching or adjusting your library configuration to remove the vulnerable functionality.

References