PT-2018-2773 · Fasterxml+3 · Jackson-Databind+3
Publicado
2018-05-10
·
Atualizado
2024-04-03
·
CVE-2018-11307
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FasterXML jackson-databind versions 2.0.0 through 2.9.5
Description
The issue is related to the shortcomings of the deserialization mechanism in the jackson-databind library. Exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content.
Recommendations
For versions 2.0.0 through 2.7.9.3, update to version 2.7.9.4.
For versions 2.8.0 through 2.8.11.1, update to version 2.8.11.2.
For versions 2.9.0 through 2.9.5, update to version 2.9.6.
As a temporary workaround, consider disabling the use of Jackson default typing until a patch is available. Restrict access to gadget classes from iBatis to minimize the risk of exploitation.
Exploit
Correção
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Ubuntu
Ibatis
Jackson-Databind