CVE-2018-5968
🟡 Monitoruj
Luka w jackson-databind umożliwia zdalne wykonanie kodu przez nieautoryzowane deserializacje.
CVSS
8.1
EPSS
7.2%
Exploit
none
Vendor
redhat
Opis źródłowy (NVD)
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
deserialization rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 7.2% |
| Opublikowano (NVD) | 2018-01-22 04:29:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:16:47 UTC |
Referencje
- https://access.redhat.com/errata/RHSA-2018:0478 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2018:0479 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2018:0480 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2018:0481 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2018:1525 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2019:2858 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2019:3149 ([email protected]) [Third Party Advisory]
- https://github.com/FasterXML/jackson-databind/issues/1899 ([email protected]) [Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20180423-0002/ ([email protected]) [Third Party Advisory]
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us ([email protected]) [Third Party Advisory]
- https://www.debian.org/security/2018/dsa-4114 ([email protected]) [Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuoct2020.html ([email protected]) [Third Party Advisory]