PT-2007-1133 · Fasterxml+3 · Jackson-Databind+3

Publicado

2007-04-10

·

Atualizado

2024-06-15

·

CVE-2018-7489

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: FasterXML jackson-databind versions 2.6.0 through 2.6.7.4 FasterXML jackson-databind versions 2.7.0 through 2.7.9.2 FasterXML jackson-databind versions 2.8.0 through 2.8.11.0 FasterXML jackson-databind versions 2.9.0 through 2.9.4
Description: The issue is related to the ObjectMapper component of the FasterXML jackson-databind library, which can lead to the restoration of untrusted data structures in memory. This can be exploited by a remote attacker to bypass blacklist restrictions and execute arbitrary code using specially crafted JSON data. The vulnerability is exploitable by sending malicious JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.
Recommendations: For FasterXML jackson-databind versions 2.6.0 through 2.6.7.4, update to version 2.6.7.5 or later. For FasterXML jackson-databind versions 2.7.0 through 2.7.9.2, update to version 2.7.9.3 or later. For FasterXML jackson-databind versions 2.8.0 through 2.8.11.0, update to version 2.8.11.1 or later. For FasterXML jackson-databind versions 2.9.0 through 2.9.4, update to version 2.9.5 or later. As a temporary workaround, consider restricting access to the readValue method of the ObjectMapper to minimize the risk of exploitation.

Exploit

Correção

RCE

Incomplete List of Disallowed Inputs

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2262
BDU:2018-00945
CVE-2018-7489
DSA-4190-1
GHSA-CGGJ-FVV3-CQWV
OPENSUSE-SU-2024:10868-1
OPENSUSE-SU-2024:10886-1
RHSA-2018:1448
RHSA-2018:1449
RHSA-2018:1450
RHSA-2018:1451
RHSA-2018:2089
RHSA-2018:2090

Produtos afetados

Alt Linux
Oracle Weblogic Server
C3P0
Jackson-Databind