PT-2018-3240 · Fasterxml · Jackson

Published

2018-12-20

·

Updated

2021-03-18

·

CVE-2018-1000873

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Fasterxml Jackson versions prior to 2.9.8
Description The issue is related to improper input validation in Jackson-Modules-Java8, which can result in a denial-of-service (DoS) when the victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in version 2.9.8.
Recommendations For versions prior to 2.9.8, update to version 2.9.8 or later to resolve the issue. As a temporary workaround, consider restricting the deserialization of time values with large nanoseconds fields to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04401
CVE-2018-1000873
GHSA-H4X4-5QP2-WP46

Affected Products

Jackson