Description
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4190-1 | jackson-databind security update |
Github GHSA |
GHSA-cggj-fvv3-cqwv | FasterXML jackson-databind allows unauthenticated remote code execution |
References
History
Fri, 23 Aug 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7 |
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Fasterxml
Subscribe
Jackson-databind
Subscribe
Oracle
Subscribe
Communications Billing And Revenue Management
Subscribe
Communications Instant Messaging Server
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Application Platform Cd
Subscribe
Jboss Fuse
Subscribe
Openshift
Subscribe
Openshift Application Runtimes
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T06:31:03.738Z
Reserved: 2018-02-26T00:00:00.000Z
Link: CVE-2018-7489
No data.
Status : Modified
Published: 2018-02-26T15:29:00.417
Modified: 2024-11-21T04:12:13.653
Link: CVE-2018-7489
OpenCVE Enrichment
No data.
Debian DSA
Github GHSA