Описание
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
A flaw was discovered in jackson-databind, where it would permit polymorphic deserialization of a malicious object using the OpenJPA class. An attacker could use this flaw to execute arbitrary code.
Отчет
Red Hat Satellite 6 is not affected by this issue, since its candlepin component doesn't bundle openjpa jar. Red Hat Virtualization 4 is not affected by this issue, since its candlepin component doesn't bundle openjpa jar. Red Hat OpenStack Platform ships OpenDaylight, which contains the vulnerable jackson-databind. However, OpenDaylight does not expose jackson-databind in a way that would make it vulnerable, lowering the impact of the vulnerability for OpenDaylight. As such, Red Hat will not be providing a fix for OpenDaylight at this time.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | jackson-databind | Not affected | ||
| Red Hat JBoss A-MQ 6 | jackson-databind | Affected | ||
| Red Hat JBoss Enterprise Application Platform 6 | jackson-databind | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | jackson-databind | Affected | ||
| Red Hat JBoss Fuse Integration Service 2 | jackson-databind | Affected | ||
| Red Hat JBoss Operations Network 3 | Core Server | Not affected | ||
| Red Hat Mobile Application Platform 4 | jackson-databind | Not affected | ||
| Red Hat OpenShift Application Runtimes | jackson-databind | Affected | ||
| Red Hat OpenShift Container Platform 3.10 | elasticsearch-cloud-kubernetes | Affected | ||
| Red Hat OpenShift Container Platform 3.10 | openshift-elasticsearch-plugin | Affected |
Показывать по
Дополнительная информация
Статус:
7.3 High
CVSS3
Связанные уязвимости
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to h ...
Deserialization of Untrusted Data in jackson-databind
Уязвимость функции FasterXML Java-библиотеки для грамматического разбора JSON файлов jackson-databind, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
7.3 High
CVSS3