CVE-2019-12384 is a deserialization of untrusted data vulnerability in FasterXML jackson-databind 2.x before 2.9.9.1. jackson-databind failed to block logback-core classes from polymorphic deserialization. An attacker who can supply crafted serialized input to an application using unsafe polymorphic type resolution can cause instantiation of a logback-core gadget. The resulting impact depends on the classes available in the target application's classpath and may include remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (14 hidden).
This repository is a proof-of-concept exploit demonstrating remote code execution via unsafe deserialization in Java applications using the Jackson-databind library (version 2.9.8) in conjunction with the H2 database (version 1.4.199). The main exploit logic is in 'src/main/java/Main.java', which crafts malicious JSON payloads that, when deserialized, trigger either the H2 database's INIT parameter to load and execute a remote SQL script (from 'http://localhost:8000/exec.sql') or a JNDI lookup to an RMI server ('rmi://127.0.0.1:1099/Exploit'). The README provides setup instructions, including creating a SQL script that defines an ALIAS for executing system commands. The exploit demonstrates the ability to execute arbitrary commands (e.g., opening Calculator) on the target system. The repository includes Maven configuration for dependencies and is structured as a typical Java Maven project. No detection scripts or fake code are present; the code is a functional exploit POC.
This repository provides an operational exploit for CVE-2019-12384, a remote code execution vulnerability in the Jackson-databind library when used with certain gadgets and the H2 database. The main exploit script (CVE-2019-12384.sh) sets up a symlink to the JRuby interpreter and executes a Ruby script (test.rb, described in the README) that deserializes a crafted payload. The payload leverages the H2 database's ability to load and execute an external SQL script via the INIT parameter in a JDBC URL. The SQL script (inject.sql) defines a Java alias that executes arbitrary shell commands, and then calls it to write the output of 'id' to a file (exploited.txt), demonstrating code execution as root. The exploit requires a local HTTP server to serve inject.sql. The repository includes a full JRuby distribution and Bundler gem files, but the exploit logic is contained in the shell script, SQL file, and the Ruby deserialization payload. The attack vector is network-based, exploiting deserialization over a service that accepts untrusted data and connects to an attacker-controlled HTTP server.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A network-accessible vulnerability with high attack complexity and no required privileges or user interaction, resulting in high confidentiality impact according to the listed CVSS v3 vector.
A Jackson Databind polymorphic-deserialization vulnerability that can lead to remote code execution through the logback-core class.
Jackson Databind polymorphic-deserialization flaw that can lead to remote code execution through logback-core.
A Jackson Databind polymorphic-deserialization flaw that fails to block the logback-core class and can lead to remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.