Описание
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
A flaw was discovered in jackson-databind, where it would permit polymorphic deserialization of a malicious object using slf4j classes. An attacker could use this flaw to execute arbitrary code.
Отчет
This vulnerability in jackson-databind involves exploiting CVE-2018-1088 against slf4j, which was fixed in Red Hat products through the errata referenced at https://access.redhat.com/security/cve/cve-2018-8088. Applications that link only slf4j versions including that fix are not vulnerable to this vulnerability. Red Hat Satellite 6 is not affected by this issue, since its candlepin component doesn't bundle slf4j-ext jar.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | jackson-databind | Not affected | ||
| Red Hat JBoss A-MQ 6 | jackson-databind | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 6 | jackson-databind | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | jackson-databind | Affected | ||
| Red Hat JBoss Enterprise Application Platform Continuous Delivery | jackson-databind | Affected | ||
| Red Hat JBoss Fuse Integration Service 2 | jackson-databind | Affected | ||
| Red Hat JBoss Operations Network 3 | Core Server | Not affected | ||
| Red Hat Mobile Application Platform 4 | jackson-databind | Not affected | ||
| Red Hat OpenShift Application Runtimes | jackson-databind | Affected | ||
| Red Hat OpenShift Container Platform 3.10 | elasticsearch-cloud-kubernetes | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attacke ...
Уязвимость библиотеки Jackson-databind, вызванная отсутствием защиты класса slf4j-ext от полиморфной десериализации, позволяющая нарушителю выполнить произвольный код
EPSS
8.1 High
CVSS3