Back to search
CVE-2018-7489
Published: Feb 26, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
103203
vdb-entry
x_refsource_BID
RHSA-2018:1448
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1449
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2938
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1450
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2090
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2939
vendor-advisory
x_refsource_REDHAT
1041890
vdb-entry
x_refsource_SECTRACK
1040693
vdb-entry
x_refsource_SECTRACK
RHSA-2018:1786
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1451
vendor-advisory
x_refsource_REDHAT
DSA-4190
vendor-advisory
x_refsource_DEBIAN
RHSA-2018:1447
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2088
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2089
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2858
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3149
vendor-advisory
x_refsource_REDHAT
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
x_refsource_CONFIRM
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
x_refsource_CONFIRM
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
x_refsource_CONFIRM
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
x_refsource_CONFIRM
https://www.oracle.com/security-alerts/cpuoct2020.html
x_refsource_MISC
https://security.netapp.com/advisory/ntap-20180328-0001/
x_refsource_CONFIRM
https://github.com/FasterXML/jackson-databind/issues/1931
x_refsource_CONFIRM
[druid-commits] 20210324 [GitHub] [druid] jihoonson opened a new pull request #11030: Suppress cves
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now