Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7525

Опубликовано: 06 фев. 2018
Источник: debian

Описание

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jackson-databindfixed2.9.1-1package
libjackson-json-javafixed1.9.13-2package
libjackson-json-javafixed1.9.13-2~deb10u1busterpackage

Примечания

  • https://github.com/FasterXML/jackson-databind/issues/1599

  • For libjackson-json-java:

  • https://github.com/FasterXML/jackson-1/commit/9ac68db819bce7b9546bc4bf1c44f82ca910fa31

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

CVSS3: 8.1
redhat
больше 8 лет назад

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

CVSS3: 9.8
nvd
около 8 лет назад

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

CVSS3: 9.8
github
больше 7 лет назад

jackson-databind is vulnerable to a deserialization flaw

CVSS3: 9.8
fstec
почти 9 лет назад

Уязвимость метода readValue класса ObjectMapper библиотеки Jackson-databind, связанная с восстановлением в памяти недостоверной структуры данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании