Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5968

Опубликовано: 22 янв. 2018
Источник: debian
EPSS Низкий

Описание

FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jackson-databindfixed2.9.4-1package

Примечания

  • https://github.com/FasterXML/jackson-databind/issues/1899

  • https://github.com/FasterXML/jackson-databind/commit/038b471e2efde2e8f96b4e0be958d3e5a1ff1d05

EPSS

Процентиль: 82%
0.01738
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 8 лет назад

FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.

CVSS3: 8.1
redhat
около 8 лет назад

FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.

CVSS3: 8.1
nvd
около 8 лет назад

FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.

CVSS3: 8.1
github
больше 5 лет назад

Deserialization of Untrusted Data in jackson-databind

CVSS3: 8.1
fstec
около 8 лет назад

Уязвимость библиотеки Jackson-databind, связанная с недостатками механизма десериализации, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 82%
0.01738
Низкий