Description
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4114-1 | jackson-databind security update |
EUVD |
EUVD-2020-0519 | FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist. |
Github GHSA |
GHSA-w3f4-3q6j-rh82 | Deserialization of Untrusted Data in jackson-databind |
References
History
Fri, 23 Aug 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7 |
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Fasterxml
Subscribe
Jackson-databind
Subscribe
Netapp
Subscribe
E-series Santricity Os Controller
Subscribe
E-series Santricity Web Services Proxy
Subscribe
Oncommand Shift
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Server
Subscribe
Jboss Enterprise Application Platform
Subscribe
Openshift
Subscribe
Openshift Container Platform
Subscribe
Virtualization
Subscribe
Virtualization Host
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T05:47:56.169Z
Reserved: 2018-01-21T00:00:00.000Z
Link: CVE-2018-5968
No data.
Status : Modified
Published: 2018-01-22T04:29:00.327
Modified: 2024-11-21T04:09:46.533
Link: CVE-2018-5968
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA