Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10202

Опубликовано: 30 сент. 2019
Источник: redhat
CVSS3: 8.1

Описание

A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6codehausOut of support scope
Red Hat Decision Manager 7codehausNot affected
Red Hat JBoss A-MQ 6codehausOut of support scope
Red Hat JBoss BRMS 5codehausOut of support scope
Red Hat JBoss BRMS 6codehausOut of support scope
Red Hat JBoss Data Grid 7codehausNot affected
Red Hat JBoss Data Virtualization 6codehausOut of support scope
Red Hat JBoss Enterprise Application Platform 5codehausOut of support scope
Red Hat JBoss Enterprise Application Platform 6codehausOut of support scope
Red Hat JBoss Fuse 6codehausOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=1731271codehaus: incomplete fix for unsafe deserialization in jackson-databind vulnerabilities

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 6 лет назад

A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.

CVSS3: 9.8
github
больше 3 лет назад

Deserialization of Untrusted Data in org.codehaus.jackson:jackson-mapper-asl

CVSS3: 8.1
fstec
больше 6 лет назад

Уязвимость среды разработки программного обеспечения Codehaus платформы JBoss Enterprise Application Platform, позволяющая нарушителю выполнить произвольный код

8.1 High

CVSS3