Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0420 | A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code. |
Github GHSA |
GHSA-cf6r-3wgc-h863 | Polymorphic deserialization of malicious object in jackson-databind |
Thu, 08 Oct 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-08T21:03:20.256Z
Reserved: 2019-08-10T00:00:00.000Z
Link: CVE-2019-14892
Updated: 2024-08-05T00:26:39.136Z
Status : Modified
Published: 2020-03-02T17:15:17.813
Modified: 2026-10-08T21:17:14.407
Link: CVE-2019-14892
OpenCVE Enrichment
No data.
EUVD
Github GHSA