PT-2018-2242 · Fasterxml+2 · Jackson-Databind+2

Published

2018-05-29

·

Updated

2021-03-15

·

CVE-2018-12023

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FasterXML jackson-databind versions prior to 2.7.9.4 FasterXML jackson-databind versions prior to 2.8.11.2 FasterXML jackson-databind versions prior to 2.9.6
Description An issue in FasterXML jackson-databind allows for the execution of a malicious payload when Default Typing is enabled and an attacker can provide an LDAP service to access. The vulnerability is related to the deserialization of untrusted data, which can lead to remote code execution. This can impact the confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 2.7.9.4, update to version 2.7.9.4 or later. For versions prior to 2.8.11.2, update to version 2.8.11.2 or later. For versions prior to 2.9.6, update to version 2.9.6 or later. As a temporary workaround, consider disabling Default Typing until a patch is available. Restrict access to the Oracle JDBC jar in the classpath to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2262
BDU:2019-00296
BDU:2019-01765
CVE-2018-12023
DLA-1703-1
DSA-4452-1
GHSA-6WQP-V4V6-C87C
OPENSUSE-SU-2024:10868-1
RHSA-2019:0782
RHSA-2019:1107
RHSA-2019:1108
USN-4813-1

Affected Products

Alt Linux
Ubuntu
Jackson-Databind