Details
Assignee
UnassignedUnassignedReporter
onms security jiraonms security jiraLabels
Priority
Trivial
Details
Details
Assignee
Unassigned
UnassignedReporter
onms security jira
onms security jiraLabels
Priority
PagerDuty
PagerDuty
PagerDuty
Created July 21, 2023 at 10:47 PM
Updated July 21, 2023 at 10:47 PM
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing com.mysql.cj.jdbc.admin.MiniAdmin validation.
Repository: OpenNMS/kafka-event-mirrorer (https://github.com/OpenNMS/kafka-event-mirrorer)
Dependabot: https://github.com/OpenNMS/kafka-event-mirrorer/security/dependabot/1
CVE: CVE-2019-12086
CVSS: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
GHSA: GHSA-5ww9-j83m-q7qx
Severity: high
Ecosystem: maven
Package Name: com.fasterxml.jackson.core:jackson-databind
Vulnerable Version Range: >= 2.0.0, < 2.9.9
First Patched Version: 2.9.9