FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-jackson-databind | Feb 16, 2018 | Jan 21, 2018 | |
| Red Hat Jboss Eap | red-hat-jboss-eap-upgrade-latest | Sep 19, 2024 | Jan 18, 2018 | |
| Redhat Openshift | linuxrpm-upgrade-logging | Oct 8, 2019 | Jan 22, 2018 | |
| Ubuntu | ubuntu-pro-upgrade-jackson-databindubuntu-upgrade-jackson-databind | Nov 19, 2024 | Jan 22, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub