PT-2018-2773 · Fasterxml+3 · Jackson-Databind+3

Published

2018-05-10

·

Updated

2024-04-03

·

CVE-2018-11307

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FasterXML jackson-databind versions 2.0.0 through 2.9.5
Description The issue is related to the shortcomings of the deserialization mechanism in the jackson-databind library. Exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content.
Recommendations For versions 2.0.0 through 2.7.9.3, update to version 2.7.9.4. For versions 2.8.0 through 2.8.11.1, update to version 2.8.11.2. For versions 2.9.0 through 2.9.5, update to version 2.9.6. As a temporary workaround, consider disabling the use of Jackson default typing until a patch is available. Restrict access to gadget classes from iBatis to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2262
BDU:2019-01771
CVE-2018-11307
DLA-1703-1
DSA-4452-1
GHSA-QR7J-H6GG-JMGC
OPENSUSE-SU-2024:10868-1
RHSA-2019:0782
RHSA-2019:1107
RHSA-2019:1108
USN-4813-1

Affected Products

Alt Linux
Ubuntu
Ibatis
Jackson-Databind