Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (2)
Add CVE-2019-12086.patch
· 33fb5ff9
Markus Koschany
authored
May 18, 2019
33fb5ff9
Update changelog
· 19043247
Markus Koschany
authored
May 18, 2019
19043247
Show whitespace changes
Inline
Side-by-side
debian/changelog
View file @
19043247
jackson-databind (2.9.8-2) unstable; urgency=medium
* Team upload.
* Fix CVE-2019-12086:
A Polymorphic Typing issue was discovered in jackson-databind. When
Default Typing is enabled (either globally or for a specific property) for
an externally exposed JSON endpoint, the service has the
mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an
attacker can host a crafted MySQL server reachable by the victim, an
attacker can send a crafted JSON message that allows them to read arbitrary
local files on the server. This occurs because of missing
com.mysql.cj.jdbc.admin.MiniAdmin validation. (Closes: #929177)
-- Markus Koschany <apo@debian.org> Sat, 18 May 2019 20:31:28 +0200
jackson-databind (2.9.8-1) unstable; urgency=medium
* Team upload.
...
...
debian/patches/CVE-2019-12086.patch
0 → 100644
View file @
19043247
From: Markus Koschany <apo@debian.org>
Date: Sat, 18 May 2019 20:29:23 +0200
Subject: CVE-2019-12086
Bug-Debian: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929177
Bug-Upstream: https://github.com/FasterXML/jackson-databind/issues/2326
Origin: https://github.com/FasterXML/jackson-databind/commit/dda513bd7251b4f32b7b60b1c13740e3b5a43024
---
.../com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java | 3 +++
1 file changed, 3 insertions(+)
diff --git a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
index 30adb94..a17cdf5 100644
--- a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
+++ b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
@@ -80,6 +80,9 @@
public class SubTypeValidator
s.add("org.apache.openjpa.ee.JNDIManagedRuntime");
s.add("org.apache.axis2.transport.jms.JMSOutTransportInfo");
+ // [databind#2326] (2.9.9): one more 3rd party gadget
+ s.add("com.mysql.cj.jdbc.admin.MiniAdmin");
+
DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s);
}
debian/patches/series
0 → 100644
View file @
19043247
CVE-2019-12086.patch