PT-2018-2242 · Fasterxml+2 · Jackson-Databind+2

Publicado

2018-05-29

·

Atualizado

2021-03-15

·

CVE-2018-12023

CVSS v2.0

7.6

Alta

VetorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FasterXML jackson-databind versions prior to 2.7.9.4 FasterXML jackson-databind versions prior to 2.8.11.2 FasterXML jackson-databind versions prior to 2.9.6
Description An issue in FasterXML jackson-databind allows for the execution of a malicious payload when Default Typing is enabled and an attacker can provide an LDAP service to access. The vulnerability is related to the deserialization of untrusted data, which can lead to remote code execution. This can impact the confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 2.7.9.4, update to version 2.7.9.4 or later. For versions prior to 2.8.11.2, update to version 2.8.11.2 or later. For versions prior to 2.9.6, update to version 2.9.6 or later. As a temporary workaround, consider disabling Default Typing until a patch is available. Restrict access to the Oracle JDBC jar in the classpath to minimize the risk of exploitation.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2262
BDU:2019-00296
BDU:2019-01765
CVE-2018-12023
DLA-1703-1
DSA-4452-1
GHSA-6WQP-V4V6-C87C
OPENSUSE-SU-2024:10868-1
RHSA-2019:0782
RHSA-2019:1107
RHSA-2019:1108
USN-4813-1

Produtos afetados

Alt Linux
Ubuntu
Jackson-Databind