Vulnerability record · CVE-2019-12384 · published 24 June 2019
CVE-2019-12384: Jackson-databind polymorphic deserialization fails to block logback-core class
Fasterxml · Jackson Databind
FasterXML jackson-databind 2.x before 2.9.9.1 does not block the logback-core class from polymorphic deserialization, allowing untrusted data to instantiate unintended classes. Depending on what is on the classpath, this can escalate to remote code execution, so any service that deserializes attacker-influenced JSON with a vulnerable version is at risk.
Description
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw is a deserialization issue that can reach remote code execution, has a very high EPSS percentile, and affects widely deployed jackson-databind, though the CVSS base score is only 5.9 and no KEV listing exists.
What it is
FasterXML jackson-databind 2.x before 2.9.9.1 does not block the logback-core class from polymorphic deserialization, allowing untrusted data to instantiate unintended classes. Depending on what is on the classpath, this can escalate to remote code execution, so any service that deserializes attacker-influenced JSON with a vulnerable version is at risk.
Impact
An attacker can trigger deserialization of unintended classes, with a variety of impacts depending on the classpath; where suitable gadget classes are present, remote code execution is possible. The CVSS vector rates confidentiality impact as high, with no integrity or availability impact recorded.
Attack surface
Reached over the network by submitting crafted JSON to an endpoint that uses jackson-databind polymorphic deserialization; no authentication or user interaction is required per the CVSS vector. Exploitability depends on the application enabling default typing or otherwise accepting polymorphic type information, and on the classes present on the classpath.
Exploitation
Not listed in CISA KEV and no ransomware use is documented. EPSS is high (about 45% 30-day probability, 98.7th percentile), and public research references describe Jackson gadget chains, but the record does not confirm in-the-wild exploitation.
What to do
- Upgrade jackson-databind to 2.9.9.1 or later, or apply the vendor patch referenced in the GitHub compare link.
- Apply the Red Hat errata listed in the references for affected Enterprise Linux and related products.
- Disable or restrict polymorphic default typing and avoid deserializing untrusted JSON into Object or generic types.
- Where default typing is required, use a strict allowlist of permitted classes and exclude logback-core and known gadget classes.
- Remove unnecessary gadget-capable libraries such as logback-core from the classpath of services that deserialize untrusted input.
Detection
- Search application and dependency inventories for jackson-databind versions below 2.9.9.1 and for logback-core on the same classpath.
- Monitor JSON request bodies for polymorphic type markers such as @class or @type referencing unexpected or gadget classes.
- Alert on deserialization errors or class-loading events involving logback-core or other gadget classes in application logs.
- Review outbound network connections and process execution spawned by Java services that handle JSON input for signs of post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-12384 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-12384), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.