CVE-2019-14439

Priority
Description
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x
before 2.9.9.2. This occurs when Default Typing is enabled (either globally
or for a specific property) for an externally exposed JSON endpoint and the
service has the logback jar in the classpath.
Notes
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):not-affected (code not present)
Ubuntu 18.04 LTS (Bionic Beaver):needed
Ubuntu 19.04 (Disco Dingo):needed
Ubuntu 19.10 (Eoan):not-affected (2.9.9.3-1)
More Information

Updated: 2019-10-18 02:45:07 UTC (commit cccfc4426d8c1fbf582a89d981fe7fc812124543)