RHSA-2019:2720HighCVSS 8.1
Red Hat Security Advisory: pki-deps:10.6 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2019-12384 — jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution
🎯 Affected products74
- Red Hat Enterprise Linux AppStream (v. 8)
- apache-commons-collections-0:3.2.2-10.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- apache-commons-collections-0:3.2.2-10.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- apache-commons-lang-0:2.6-21.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- apache-commons-lang-0:2.6-21.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bea-stax-0:1.2.0-16.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- bea-stax-api-0:1.2.0-16.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-fastinfoset-0:1.2.13-9.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-fastinfoset-0:1.2.13-9.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-jaxb-0:2.2.11-11.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-jaxb-api-0:2.2.12-8.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-jaxb-api-0:2.2.12-8.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-jaxb-core-0:2.2.11-11.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-jaxb-runtime-0:2.2.11-11.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- glassfish-jaxb-txw2-0:2.2.11-11.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-annotations-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-annotations-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-core-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-core-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-databind-0:2.9.9.2-1.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-databind-0:2.9.9.2-1.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-jaxrs-json-provider-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-jaxrs-providers-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-jaxrs-providers-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-module-jaxb-annotations-0:2.7.6-4.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jackson-module-jaxb-annotations-0:2.7.6-4.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jakarta-commons-httpclient-1:3.1-28.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- jakarta-commons-httpclient-1:3.1-28.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- javassist-0:3.18.1-8.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- javassist-0:3.18.1-8.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +44 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`