FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete, leading to resultant weaknesses.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jackson-databind | Fasterxml | 2.0.0 (including) | 2.6.7.3 (excluding) |
Jackson-databind | Fasterxml | 2.7.0 (including) | 2.7.9.2 (excluding) |
Jackson-databind | Fasterxml | 2.8.0 (including) | 2.8.11.1 (excluding) |
Jackson-databind | Fasterxml | 2.9.0 (including) | 2.9.4 (excluding) |
Red Hat JBoss EAP 7 | RedHat | jackson-databind | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-activemq-artemis-0:1.5.5.009-1.redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-apache-cxf-0:3.1.13-1.redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-glassfish-jsf-0:2.2.13-6.SP5_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-hibernate-0:5.1.12-1.Final_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-infinispan-0:8.2.9-1.Final_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-ironjacamar-0:1.4.7-1.Final_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jackson-annotations-0:2.8.11-1.redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jackson-core-0:2.8.11-1.redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jackson-databind-0:2.8.11-1.redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jackson-jaxrs-providers-0:2.8.11-1.redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jackson-module-jaxb-annotations-0:2.8.11-1.redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jackson-modules-java8-0:2.8.11-1.redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jboss-logmanager-0:2.0.8-1.Final_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jboss-server-migration-0:1.0.3-6.Final_redhat_6.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jbossws-cxf-0:5.1.10-1.Final_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-narayana-0:5.5.31-1.Final_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-picketlink-bindings-0:2.5.5-10.SP9_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-picketlink-federation-0:2.5.5-10.SP9_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-resteasy-0:3.0.25-1.Final_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-undertow-0:1.4.18-4.SP2_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-undertow-jastow-0:2.0.3-1.Final_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-wildfly-0:7.1.1-4.GA_redhat_2.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-wildfly-elytron-0:1.1.8-1.Final_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-wildfly-http-client-0:1.0.9-1.Final_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-wildfly-javadocs-0:7.1.1-3.GA_redhat_2.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-wss4j-0:2.1.11-1.redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-xml-security-0:2.0.9-1.redhat_1.1.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jboss-ec2-eap-0:7.1.1-3.1.GA_redhat_3.ep7.el6 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-activemq-artemis-0:1.5.5.009-1.redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-apache-cxf-0:3.1.13-1.redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-glassfish-jsf-0:2.2.13-6.SP5_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-hibernate-0:5.1.12-1.Final_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-infinispan-0:8.2.9-1.Final_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-ironjacamar-0:1.4.7-1.Final_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jackson-annotations-0:2.8.11-1.redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jackson-core-0:2.8.11-1.redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jackson-databind-0:2.8.11-1.redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jackson-jaxrs-providers-0:2.8.11-1.redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jackson-module-jaxb-annotations-0:2.8.11-1.redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jackson-modules-java8-0:2.8.11-1.redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jboss-logmanager-0:2.0.8-1.Final_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jboss-server-migration-0:1.0.3-6.Final_redhat_6.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jbossws-cxf-0:5.1.10-1.Final_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-narayana-0:5.5.31-1.Final_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-picketlink-bindings-0:2.5.5-10.SP9_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-picketlink-federation-0:2.5.5-10.SP9_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-resteasy-0:3.0.25-1.Final_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-undertow-0:1.4.18-4.SP2_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-undertow-jastow-0:2.0.3-1.Final_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-wildfly-0:7.1.1-4.GA_redhat_2.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-wildfly-elytron-0:1.1.8-1.Final_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-wildfly-http-client-0:1.0.9-1.Final_redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-wildfly-javadocs-0:7.1.1-3.GA_redhat_2.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-wss4j-0:2.1.11-1.redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-xml-security-0:2.0.9-1.redhat_1.1.ep7.el7 | * |
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jboss-ec2-eap-0:7.1.1-3.1.GA_redhat_3.ep7.el7 | * |
Red Hat OpenShift Container Platform 3.11 | RedHat | openshift3/ose-logging-elasticsearch5:v3.11.153-2 | * |
Red Hat OpenShift Container Platform 4.1 | RedHat | openshift4/ose-logging-elasticsearch5:v4.1.18-201909201915 | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | rhvm-appliance-0:4.2-20180504.0 | * |
Jackson-databind | Ubuntu | artful | * |
Jackson-databind | Ubuntu | esm-apps/xenial | * |
Jackson-databind | Ubuntu | trusty | * |
Jackson-databind | Ubuntu | trusty/esm | * |
Jackson-databind | Ubuntu | upstream | * |
Jackson-databind | Ubuntu | xenial | * |