VYPR
Critical severity9.8NVD Advisory· Published Jul 29, 2019· Updated Jun 17, 2026

CVE-2019-14379

CVE-2019-14379

Description

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.fasterxml.jackson.core:jackson-databindMaven
>= 2.9.0, < 2.9.9.22.9.9.2
com.fasterxml.jackson.core:jackson-databindMaven
>= 2.8.0, < 2.8.11.42.8.11.4
com.fasterxml.jackson.core:jackson-databindMaven
< 2.7.9.62.7.9.6

Affected products

51

Patches

Vulnerability mechanics

References

92

News mentions

0

No linked articles in our index yet.