CVE-2018-5968High· 8.1▾ TwilightFasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two diffe…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 1.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
7.2%
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
jackson-databind >= 2.0.0, < 2.6.7.3jackson-databind >= 2.7.0, < 2.7.9.2jackson-databind >= 2.8.0, < 2.8.11.1jackson-databind >= 2.9.0, < 2.9.4debian_linux = 8.0debian_linux = 9.0openshift_container_platform = 4.1virtualization = 4.0virtualization_host = 4.0jboss_enterprise_application_platform = 7.1openshift_container_platform = 3.11e-series_santricity_os_controller >= 11.0.0, <= 11.60.3e-series_santricity_web_services_proxyoncommand_shiftUpgrade past the affected range:
jackson-databind 2.9.4Connected by shared product, vendor, weakness, or advisory.
CVE-2017-15095Critical· 9.8A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of th…
CVE-2017-7525Critical· 9.8A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue meth…
CVE-2019-14893Critical· 9.8A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic ty…
CVE-2018-11307Critical· 9.8An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5
CVE-2019-12086High· 7.5A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9
CVE-2019-12384Medium· 5.9FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization