CVE-2019-14439 is a polymorphic typing vulnerability in FasterXML jackson-databind versions prior to 2.9.9.2, affecting products from vendors like Apache, Debian, and Oracle. This flaw arises when default typing is enabled for an exposed JSON endpoint and the logback jar is present in the classpath. With a CVSS score of 7.5 (High), it presents a low-complexity network attack vector that can lead to high confidentiality impact without requiring user interaction or privileges. While the vulnerability has a high FAUCET risk score, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.6.7.3CPE matchmatch criteria | cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* | ||
>= 2.7.0, < 2.7.9.6CPE matchmatch criteria | cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* | ||
>= 2.8.0, < 2.8.11.4CPE matchmatch criteria | cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* | ||
>= 2.9.0, < 2.9.9.2CPE matchmatch criteria | cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025
Aug 6, 2025Deserialization of untrusted data in FasterXML jackson-databind
Aug 1, 2019jackson-databind: Polymorphic typing issue related to logback/JNDI
Jul 30, 2019