Bug 1755831 (CVE-2019-16335) - CVE-2019-16335 jackson-databind: polymorphic typing issue related to com.zaxxer.hikari.HikariDataSource
Summary: CVE-2019-16335 jackson-databind: polymorphic typing issue related to com.zaxx...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2019-16335
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1760278 1762564 1762570 1762571 1762572 1781719 1755832 1760279 1762566 1762567 1762568 1762569
Blocks: 1755833
TreeView+ depends on / blocked
 
Reported: 2019-09-26 10:04 UTC by Dhananjay Arunesh
Modified: 2020-01-21 03:46 UTC (History)
114 users (show)

Fixed In Version: jackson-databind 2.9.10
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-10-24 12:51:20 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:3200 None None None 2019-10-24 09:18:26 UTC
Red Hat Product Errata RHSA-2020:0159 None None None 2020-01-21 02:56:20 UTC
Red Hat Product Errata RHSA-2020:0160 None None None 2020-01-21 03:46:28 UTC
Red Hat Product Errata RHSA-2020:0161 None None None 2020-01-21 03:21:40 UTC
Red Hat Product Errata RHSA-2020:0164 None None None 2020-01-21 02:23:46 UTC

Description Dhananjay Arunesh 2019-09-26 10:04:04 UTC
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.

Reference:
https://github.com/FasterXML/jackson-databind/issues/2449
https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E
https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1@%3Cissues.hbase.apache.org%3E

Comment 1 Dhananjay Arunesh 2019-09-26 10:04:30 UTC
Created jackson-databind tracking bugs for this issue:

Affects: fedora-all [bug 1755832]

Comment 5 Doran Moppert 2019-10-10 03:40:26 UTC
Mitigation:

This vulnerability relies on com.zaxxer.hikari.HikariDataSource being present in the application's ClassPath. Hikari is not packaged as an RPM for Red Hat Enterprise Linux or Red Hat Software Collections. Applications using jackson-databind that do not also use com.zaxxer.hikari are not impacted by this vulnerability.

A mitigation to this class of problem in jackson-databind is to not trigger polymorphic desrialization globally by using: objectMapper.enableDefaultTyping() and rather use @JsonTypeInfo on the class property to explicitly define the type information. For more information on this issue please refer to https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true

Comment 8 Cedric Buissart 🐶 2019-10-10 11:16:18 UTC
Statement:

Red Hat OpenStack Platform ships OpenDaylight, which contains the vulnerable jackson-databind. However, OpenDaylight does not expose jackson-databind in a way that would make it vulnerable, lowering the impact of the vulnerability for OpenDaylight. As such, Red Hat will not be providing a fix for OpenDaylight at this time.

Satellite 6 does not enable polymorphic unmarshmalling, which is a required configuration for the vulnerability to be used. We may update the jackson-databind dependency in a future release.

Comment 12 errata-xmlrpc 2019-10-24 09:18:22 UTC
This issue has been addressed in the following products:

  Red Hat JBoss AMQ

Via RHSA-2019:3200 https://access.redhat.com/errata/RHSA-2019:3200

Comment 13 Product Security DevOps Team 2019-10-24 12:51:20 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-16335

Comment 14 Paramvir jindal 2019-11-19 11:08:09 UTC
Marking RHSSO as affected fix because the fix version seems to be jackson-databind 2.9.10 and RHSSO 7.3.4 (latest as of today) ships jackson-databind-2.9.9.3-redhat-00001.jar.

Comment 20 Paramvir jindal 2019-12-17 09:20:47 UTC
JDG 7.3.4 ships jackson-databind-2.9.9.3-redhat-00001.jar which seems to be affected hence creating tracker for it : 

JDG/modules/system/add-ons/jdg/.overlays/layer-jdg-jboss-jdg-7.3.4.CP/com/fasterxml/jackson/core/jackson-databind/jdg-7.3/jackson-databind-2.9.9.3-redhat-00001.jar

Comment 23 errata-xmlrpc 2020-01-21 02:23:43 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2020:0164 https://access.redhat.com/errata/RHSA-2020:0164

Comment 24 errata-xmlrpc 2020-01-21 02:56:17 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6

Via RHSA-2020:0159 https://access.redhat.com/errata/RHSA-2020:0159

Comment 25 errata-xmlrpc 2020-01-21 03:21:37 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8

Via RHSA-2020:0161 https://access.redhat.com/errata/RHSA-2020:0161

Comment 26 errata-xmlrpc 2020-01-21 03:46:25 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7

Via RHSA-2020:0160 https://access.redhat.com/errata/RHSA-2020:0160


Note You need to log in before you can comment on or make changes to this bug.