CVE-2019-14892: Apache Geode

Critical severity, CVSS 9.8. EPSS: 5.6% chance of exploitation in the next 30 days.

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.

Affected products

  • Apache Geode: version 1.12.0 only
  • Fasterxml Jackson-Databind: from 2.0.0, before 2.6.7.3 (fixed in 2.6.7.3); from 2.7.0, before 2.8.11.5 (fixed in 2.8.11.5); from 2.9.0, before 2.9.10 (fixed in 2.9.10)
  • Red Hat Decision Manager: version 7.0 only
  • Red Hat JBoss Data Grid: affected versions not specified; version 7.0.0 only
  • Red Hat JBoss Enterprise Application Platform: version 7.0 only
  • Red Hat JBoss Fuse: version 7.0.0 only
  • Red Hat Openshift Container Platform: version 4.3 only
  • Red Hat Process Automation: version 7.0 only

Published 2020-03-02. Last modified 2026-10-08.