CVE-2018-12022

🟡 Monitoruj

Wykonanie złośliwego kodu w FasterXML jackson-databind umożliwia atakującemu dostęp do LDAP.

CVSS
7.5
EPSS
7.1%
Exploit
none
Vendor
redhat
Opis źródłowy (NVD)

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)7.1%
Opublikowano (NVD)2019-03-21 16:00:12 UTC
Ostatnia modyfikacja (NVD)2026-10-08 21:17:07 UTC
Referencje