RHSA-2019:2720HighCVSS 8.1

Red Hat Security Advisory: pki-deps:10.6 security update

Published
September 12, 2019
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2019-12384 — jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution

🎯 Affected products74

  • Red Hat Enterprise Linux AppStream (v. 8)
  • apache-commons-collections-0:3.2.2-10.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • apache-commons-collections-0:3.2.2-10.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • apache-commons-lang-0:2.6-21.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • apache-commons-lang-0:2.6-21.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bea-stax-0:1.2.0-16.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bea-stax-api-0:1.2.0-16.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • glassfish-fastinfoset-0:1.2.13-9.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • glassfish-fastinfoset-0:1.2.13-9.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • glassfish-jaxb-0:2.2.11-11.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • glassfish-jaxb-api-0:2.2.12-8.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • glassfish-jaxb-api-0:2.2.12-8.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • glassfish-jaxb-core-0:2.2.11-11.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • glassfish-jaxb-runtime-0:2.2.11-11.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • glassfish-jaxb-txw2-0:2.2.11-11.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • jackson-annotations-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • jackson-annotations-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • jackson-core-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • jackson-core-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • jackson-databind-0:2.9.9.2-1.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • jackson-databind-0:2.9.9.2-1.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • jackson-jaxrs-json-provider-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • jackson-jaxrs-providers-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • jackson-jaxrs-providers-0:2.9.9-1.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • jackson-module-jaxb-annotations-0:2.7.6-4.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • jackson-module-jaxb-annotations-0:2.7.6-4.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • jakarta-commons-httpclient-1:3.1-28.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • jakarta-commons-httpclient-1:3.1-28.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • javassist-0:3.18.1-8.module+el8.0.0+3892+c903d3f0.noarch (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • javassist-0:3.18.1-8.module+el8.0.0+3892+c903d3f0.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • +44 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`

🔗 References (4)