CVE-2019-14892: Apache Geode
Critical severity, CVSS 9.8. EPSS: 5.6% chance of exploitation in the next 30 days.
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
Affected products
- Apache Geode: version 1.12.0 only
- Fasterxml Jackson-Databind: from 2.0.0, before 2.6.7.3 (fixed in 2.6.7.3); from 2.7.0, before 2.8.11.5 (fixed in 2.8.11.5); from 2.9.0, before 2.9.10 (fixed in 2.9.10)
- Red Hat Decision Manager: version 7.0 only
- Red Hat JBoss Data Grid: affected versions not specified; version 7.0.0 only
- Red Hat JBoss Enterprise Application Platform: version 7.0 only
- Red Hat JBoss Fuse: version 7.0.0 only
- Red Hat Openshift Container Platform: version 4.3 only
- Red Hat Process Automation: version 7.0 only
Published 2020-03-02. Last modified 2026-10-08.