PT-2018-2773 · Fasterxml+3 · Jackson-Databind+3

Publicado

2018-05-10

·

Atualizado

2024-04-03

·

CVE-2018-11307

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FasterXML jackson-databind versions 2.0.0 through 2.9.5
Description The issue is related to the shortcomings of the deserialization mechanism in the jackson-databind library. Exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content.
Recommendations For versions 2.0.0 through 2.7.9.3, update to version 2.7.9.4. For versions 2.8.0 through 2.8.11.1, update to version 2.8.11.2. For versions 2.9.0 through 2.9.5, update to version 2.9.6. As a temporary workaround, consider disabling the use of Jackson default typing until a patch is available. Restrict access to gadget classes from iBatis to minimize the risk of exploitation.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2262
BDU:2019-01771
CVE-2018-11307
DLA-1703-1
DSA-4452-1
GHSA-QR7J-H6GG-JMGC
OPENSUSE-SU-2024:10868-1
RHSA-2019:0782
RHSA-2019:1107
RHSA-2019:1108
USN-4813-1

Produtos afetados

Alt Linux
Ubuntu
Ibatis
Jackson-Databind