A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libjackson-json-javaUpgrade jackson-databind | Nov 16, 2017 | Nov 16, 2017 |
| Oracle Missing Cpu Jul 2018 | — | Apply the July 2018 Critical Patch Update (CPU) for Oracle Database | Jul 18, 2018 | Feb 6, 2018 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Nov 2, 2017 |
| Red_hat Jboss_eap | — | — | Nov 14, 2019 | Feb 6, 2018 |
| Redhat Openshift | — | Upgrade logging | Oct 8, 2019 | Feb 6, 2018 |
| Ubuntu | — | Upgrade libjackson-json-java | Feb 19, 2021 | Nov 16, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub