QID 980763
QID 980763: Java (maven) Security Update for com.fasterxml.jackson.core:jackson-databind (GHSA-w3f4-3q6j-rh82)
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-w3f4-3q6j-rh82 for updates pertaining to this vulnerability.
Vendor References
- GHSA-w3f4-3q6j-rh82 -
github.com/advisories/GHSA-w3f4-3q6j-rh82
CVEs related to QID 980763
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w3f4-3q6j-rh82 | com.fasterxml.jackson.core:jackson-databind |
|