ALT-PU-2018-1722-1
Package jackson-databind updated to version 2.9.4-alt1_3jpp8 for branch sisyphus in task 206492.
Closed vulnerabilities
BDU:2019-04797
Уязвимость библиотеки Jackson-databind, связанная с недостатками механизма десериализации, позволяющая нарушителю выполнить произвольный код
BDU:2021-01382
Уязвимость метода readValue класса ObjectMapper библиотеки Jackson-databind, связанная с восстановлением в памяти недостоверной структуры данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01394
Уязвимость метода readValue класса ObjectMapper библиотеки Jackson-databind, связанная с восстановлением в памяти недостоверной структуры данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2017-15095
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 103880
- 103880
- 1039769
- 1039769
- RHSA-2017:3189
- RHSA-2017:3189
- RHSA-2017:3190
- RHSA-2017:3190
- RHSA-2018:0342
- RHSA-2018:0342
- RHSA-2018:0478
- RHSA-2018:0478
- RHSA-2018:0479
- RHSA-2018:0479
- RHSA-2018:0480
- RHSA-2018:0480
- RHSA-2018:0481
- RHSA-2018:0481
- RHSA-2018:0576
- RHSA-2018:0576
- RHSA-2018:0577
- RHSA-2018:0577
- RHSA-2018:1447
- RHSA-2018:1447
- RHSA-2018:1448
- RHSA-2018:1448
- RHSA-2018:1449
- RHSA-2018:1449
- RHSA-2018:1450
- RHSA-2018:1450
- RHSA-2018:1451
- RHSA-2018:1451
- RHSA-2018:2927
- RHSA-2018:2927
- RHSA-2019:2858
- RHSA-2019:2858
- RHSA-2019:3149
- RHSA-2019:3149
- RHSA-2019:3892
- RHSA-2019:3892
- https://github.com/FasterXML/jackson-databind/issues/1680
- https://github.com/FasterXML/jackson-databind/issues/1680
- https://github.com/FasterXML/jackson-databind/issues/1737
- https://github.com/FasterXML/jackson-databind/issues/1737
- [lucene-solr-user] 20191219 Re: CVE-2017-7525 fix for Solr 7.7.x
- [lucene-solr-user] 20191219 Re: CVE-2017-7525 fix for Solr 7.7.x
- [debian-lts-announce] 20200131 [SECURITY] [DLA 2091-1] libjackson-json-java security update
- [debian-lts-announce] 20200131 [SECURITY] [DLA 2091-1] libjackson-json-java security update
- https://security.netapp.com/advisory/ntap-20171214-0003/
- https://security.netapp.com/advisory/ntap-20171214-0003/
- DSA-4037
- DSA-4037
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Modified: 2024-11-21
CVE-2017-17485
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.
- 20180109 CVE-2017-17485: one more way of rce in jackson-databind when defaultTyping+objects are used
- 20180109 CVE-2017-17485: one more way of rce in jackson-databind when defaultTyping+objects are used
- RHSA-2018:0116
- RHSA-2018:0116
- RHSA-2018:0342
- RHSA-2018:0342
- RHSA-2018:0478
- RHSA-2018:0478
- RHSA-2018:0479
- RHSA-2018:0479
- RHSA-2018:0480
- RHSA-2018:0480
- RHSA-2018:0481
- RHSA-2018:0481
- RHSA-2018:1447
- RHSA-2018:1447
- RHSA-2018:1448
- RHSA-2018:1448
- RHSA-2018:1449
- RHSA-2018:1449
- RHSA-2018:1450
- RHSA-2018:1450
- RHSA-2018:1451
- RHSA-2018:1451
- RHSA-2018:2930
- RHSA-2018:2930
- RHSA-2019:1782
- RHSA-2019:1782
- RHSA-2019:1797
- RHSA-2019:1797
- RHSA-2019:2858
- RHSA-2019:2858
- RHSA-2019:3149
- RHSA-2019:3149
- RHSA-2019:3892
- RHSA-2019:3892
- https://github.com/FasterXML/jackson-databind/issues/1855
- https://github.com/FasterXML/jackson-databind/issues/1855
- https://github.com/irsl/jackson-rce-via-spel/
- https://github.com/irsl/jackson-rce-via-spel/
- https://security.netapp.com/advisory/ntap-20180201-0003/
- https://security.netapp.com/advisory/ntap-20180201-0003/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us
- DSA-4114
- DSA-4114
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
Modified: 2024-11-21
CVE-2017-7525
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 99623
- 99623
- 1039744
- 1039744
- 1039947
- 1039947
- 1040360
- 1040360
- RHSA-2017:1834
- RHSA-2017:1834
- RHSA-2017:1835
- RHSA-2017:1835
- RHSA-2017:1836
- RHSA-2017:1836
- RHSA-2017:1837
- RHSA-2017:1837
- RHSA-2017:1839
- RHSA-2017:1839
- RHSA-2017:1840
- RHSA-2017:1840
- RHSA-2017:2477
- RHSA-2017:2477
- RHSA-2017:2546
- RHSA-2017:2546
- RHSA-2017:2547
- RHSA-2017:2547
- RHSA-2017:2633
- RHSA-2017:2633
- RHSA-2017:2635
- RHSA-2017:2635
- RHSA-2017:2636
- RHSA-2017:2636
- RHSA-2017:2637
- RHSA-2017:2637
- RHSA-2017:2638
- RHSA-2017:2638
- RHSA-2017:3141
- RHSA-2017:3141
- RHSA-2017:3454
- RHSA-2017:3454
- RHSA-2017:3455
- RHSA-2017:3455
- RHSA-2017:3456
- RHSA-2017:3456
- RHSA-2017:3458
- RHSA-2017:3458
- RHSA-2018:0294
- RHSA-2018:0294
- RHSA-2018:0342
- RHSA-2018:0342
- RHSA-2018:1449
- RHSA-2018:1449
- RHSA-2018:1450
- RHSA-2018:1450
- RHSA-2019:0910
- RHSA-2019:0910
- RHSA-2019:2858
- RHSA-2019:2858
- RHSA-2019:3149
- RHSA-2019:3149
- https://bugzilla.redhat.com/show_bug.cgi?id=1462702
- https://bugzilla.redhat.com/show_bug.cgi?id=1462702
- https://cwiki.apache.org/confluence/display/WW/S2-055
- https://cwiki.apache.org/confluence/display/WW/S2-055
- https://github.com/FasterXML/jackson-databind/issues/1599
- https://github.com/FasterXML/jackson-databind/issues/1599
- https://github.com/FasterXML/jackson-databind/issues/1723
- https://github.com/FasterXML/jackson-databind/issues/1723
- [lucene-dev] 20190325 [jira] [Updated] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
- [lucene-dev] 20190325 [jira] [Updated] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
- [cassandra-commits] 20191113 [jira] [Created] (CASSANDRA-15416) CVE-2017-7525 ( jackson-databind is vulnerable to Remote Code Execution) on version 3.11.4
- [cassandra-commits] 20191113 [jira] [Created] (CASSANDRA-15416) CVE-2017-7525 ( jackson-databind is vulnerable to Remote Code Execution) on version 3.11.4
- [lucene-solr-user] 20191218 CVE-2017-7525 fix for Solr 7.7.x
- [lucene-solr-user] 20191218 CVE-2017-7525 fix for Solr 7.7.x
- [lucene-solr-user] 20190104 Re: SOLR v7 Security Issues Caused Denial of Use - Sonatype Application Composition Report
- [lucene-solr-user] 20190104 Re: SOLR v7 Security Issues Caused Denial of Use - Sonatype Application Composition Report
- [druid-commits] 20191115 [GitHub] [incubator-druid] ccaominh opened a new pull request #8878: Address security vulnerabilities
- [druid-commits] 20191115 [GitHub] [incubator-druid] ccaominh opened a new pull request #8878: Address security vulnerabilities
- [lucene-dev] 20190325 [jira] [Updated] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
- [lucene-dev] 20190325 [jira] [Updated] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
- [lucene-dev] 20190325 [jira] [Resolved] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
- [lucene-dev] 20190325 [jira] [Resolved] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
- [lucene-dev] 20190325 [jira] [Assigned] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
- [lucene-dev] 20190325 [jira] [Assigned] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
- [lucene-solr-user] 20191218 Re: CVE-2017-7525 fix for Solr 7.7.x
- [lucene-solr-user] 20191218 Re: CVE-2017-7525 fix for Solr 7.7.x
- [lucene-solr-user] 20191219 Re: CVE-2017-7525 fix for Solr 7.7.x
- [lucene-solr-user] 20191219 Re: CVE-2017-7525 fix for Solr 7.7.x
- [lucene-dev] 20190325 [jira] [Closed] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
- [lucene-dev] 20190325 [jira] [Closed] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
- [cassandra-commits] 20210927 [jira] [Updated] (CASSANDRA-15416) CVE-2017-7525 ( jackson-databind is vulnerable to Remote Code Execution) on version 3.11.4
- [cassandra-commits] 20210927 [jira] [Updated] (CASSANDRA-15416) CVE-2017-7525 ( jackson-databind is vulnerable to Remote Code Execution) on version 3.11.4
- [spark-issues] 20210223 [jira] [Created] (SPARK-34511) Current Security vulnerabilities in spark libraries
- [spark-issues] 20210223 [jira] [Created] (SPARK-34511) Current Security vulnerabilities in spark libraries
- [cassandra-commits] 20210927 [jira] [Commented] (CASSANDRA-15416) CVE-2017-7525 ( jackson-databind is vulnerable to Remote Code Execution) on version 3.11.4
- [cassandra-commits] 20210927 [jira] [Commented] (CASSANDRA-15416) CVE-2017-7525 ( jackson-databind is vulnerable to Remote Code Execution) on version 3.11.4
- [debian-lts-announce] 20200131 [SECURITY] [DLA 2091-1] libjackson-json-java security update
- [debian-lts-announce] 20200131 [SECURITY] [DLA 2091-1] libjackson-json-java security update
- [debian-lts-announce] 20200824 [SECURITY] [DLA 2342-1] libjackson-json-java security update
- [debian-lts-announce] 20200824 [SECURITY] [DLA 2342-1] libjackson-json-java security update
- https://security.netapp.com/advisory/ntap-20171214-0002/
- https://security.netapp.com/advisory/ntap-20171214-0002/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us
- DSA-4004
- DSA-4004
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Modified: 2024-11-21
CVE-2018-5968
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
- RHSA-2018:0478
- RHSA-2018:0478
- RHSA-2018:0479
- RHSA-2018:0479
- RHSA-2018:0480
- RHSA-2018:0480
- RHSA-2018:0481
- RHSA-2018:0481
- RHSA-2018:1525
- RHSA-2018:1525
- RHSA-2019:2858
- RHSA-2019:2858
- RHSA-2019:3149
- RHSA-2019:3149
- https://github.com/FasterXML/jackson-databind/issues/1899
- https://github.com/FasterXML/jackson-databind/issues/1899
- https://security.netapp.com/advisory/ntap-20180423-0002/
- https://security.netapp.com/advisory/ntap-20180423-0002/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us
- DSA-4114
- DSA-4114
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html