Описание
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
Отчет
Red Hat Satellite 6 is not affected by this issue, since its only supported Java runtime (openJDK) doesn't bundle the com.sun.deploy.security.ruleset.DRSHelper class. Red Hat Enterprise Virtualization 4 is not affected by this issue, since its only supported Java runtime (openJDK) doesn't bundle the com.sun.deploy.security.ruleset.DRSHelper class.
Меры по смягчению последствий
The following conditions are needed for an exploit, we recommend avoiding all if possible
- Deserialization from sources you do not control
enableDefaultTyping()@JsonTypeInfo usingid.CLASSorid.MINIMAL_CLASS`
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat BPM Suite 6 | jackson-databind | Will not fix | ||
| Red Hat Enterprise Linux 8 | jackson-databind | Not affected | ||
| Red Hat JBoss A-MQ 6 | jackson-databind | Out of support scope | ||
| Red Hat JBoss BRMS 6 | jackson-databind | Will not fix | ||
| Red Hat JBoss Data Virtualization 6 | jackson-databind | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 6 | jackson-databind | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Continuous Delivery | jackson-databind | Affected | ||
| Red Hat JBoss Fuse 6 | jackson-databind | Will not fix | ||
| Red Hat JBoss Fuse Integration Service 2 | jackson-databind | Will not fix | ||
| Red Hat JBoss Operations Network 3 | Core Server | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to c ...
XML External Entity Reference (XXE) in jackson-databind
Уязвимость библиотеки jackson-databind, связанная с ошибкой ограничения XML-ссылок на внешние объекты, позволяющая нарушителю осуществить XXE-атаку
EPSS
7.5 High
CVSS3