FasterXML Jackson-databind CVE-2018-11307 Remote Security Vulnerability
BID:109280
Info
FasterXML Jackson-databind CVE-2018-11307 Remote Security Vulnerability
| Bugtraq ID: | 109280 |
| Class: | Unknown |
| CVE: |
CVE-2018-11307 |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2018 12:00AM |
| Updated: | May 10 2018 12:00AM |
| Credit: | cowtowncoder |
| Vulnerable: |
Redhat Software Collections for RHEL 7 Redhat Single Sign-On 7.3 Redhat Single Sign-On 7.0 Redhat Openshift Application Runtimes 1.0 Redhat JBoss Fuse 6.0 Redhat JBoss Fuse 7.0 Redhat JBoss Enterprise Application Platform (for RHEL 7) 7.2 Redhat JBoss Enterprise Application Platform (for RHEL 6) 7.2 Redhat Jboss EAP 7.2 Redhat JBoss Data Virtualization 6.0.0 Redhat JBoss Data Grid 7 Redhat JBoss BRMS 6.0 Redhat JBoss BPMS 6.0 Redhat JBoss A-MQ 6.0 Oracle Utilities Advanced Spatial and Operational Analytics 2.7.0.1 Oracle Communications Instant Messaging Server 10.0.1.2.0 FasterXML jackson-databind 2.9.5 FasterXML jackson-databind 2.9.4 FasterXML jackson-databind 2.9.2 FasterXML jackson-databind 2.9.1 FasterXML jackson-databind 2.9 FasterXML jackson-databind 2.8.11 FasterXML jackson-databind 2.8.10 FasterXML jackson-databind 2.0 FasterXML jackson-databind 2.8.11.1 FasterXML jackson-databind 2.8 FasterXML jackson-databind 2.7.9.3 FasterXML jackson-databind 2.7.9.1 FasterXML jackson-databind 2.7 FasterXML jackson-databind 2.6.7.1 FasterXML jackson-databind 2.6 FasterXML jackson-databind 2.5 FasterXML jackson-databind 2.4 FasterXML jackson-databind 2.3 |
| Not Vulnerable: |
FasterXML jackson-databind 2.9.6 FasterXML jackson-databind 2.8.11.2 FasterXML jackson-databind 2.7.9.4 |
Discussion
FasterXML Jackson-databind CVE-2018-11307 Remote Security Vulnerability
FasterXML Jackson-databind is prone to a security vulnerability.
An attacker may leverage this issue to bypass certain security restrictions, perform certain unauthorized actions in the context of the affected site.
FasterXML jackson-databind 2.0.0 through 2.9.5 are vulnerable.
FasterXML Jackson-databind is prone to a security vulnerability.
An attacker may leverage this issue to bypass certain security restrictions, perform certain unauthorized actions in the context of the affected site.
FasterXML jackson-databind 2.0.0 through 2.9.5 are vulnerable.
Exploit / POC
FasterXML Jackson-databind CVE-2018-11307 Remote Security Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
FasterXML Jackson-databind CVE-2018-11307 Remote Security Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
FasterXML Jackson-databind CVE-2018-11307 Remote Security Vulnerability
References:
References:
- FasterXML/jackson-databind Home Page (FasterXML)
- CVE-2018-11307 (Red Hat)
- CVE-2018-11307 jackson-databind: Potential information exfiltration with default (Red Hat Bugzilla)
- CVE-2018-11307: Potential information exfiltration with default typing, serializ (Github)
- On Jackson CVEs: Don�??t Panic �?? Here is what you need to know ()
- Oracle Critical Patch Update Advisory - July 2019 (Oracle)
- RHSA-2019:0782 - Security Advisory (Red Hat)
- RHSA-2019:0877 - Security Advisory (Red Hat)
- RHSA-2019:1106 - Security Advisory (Red Hat)
- RHSA-2019:1107 - Security Advisory (Red Hat)
- RHSA-2019:1108 - Security Advisory (Red Hat)
- RHSA-2019:1140 - Security Advisory (Red Hat)