FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Jackson-databind | Fasterxml | 2.0.0 (including) | 2.6.7.3 (excluding) |
| Jackson-databind | Fasterxml | 2.7.0 (including) | 2.7.9.2 (excluding) |
| Jackson-databind | Fasterxml | 2.8.0 (including) | 2.8.11.1 (excluding) |
| Jackson-databind | Fasterxml | 2.9.0 (including) | 2.9.4 (excluding) |
| Red Hat JBoss EAP 7 | RedHat | jackson-databind | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-activemq-artemis-0:1.5.5.009-1.redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-apache-cxf-0:3.1.13-1.redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-glassfish-jsf-0:2.2.13-6.SP5_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-hibernate-0:5.1.12-1.Final_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-infinispan-0:8.2.9-1.Final_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-ironjacamar-0:1.4.7-1.Final_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jackson-annotations-0:2.8.11-1.redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jackson-core-0:2.8.11-1.redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jackson-databind-0:2.8.11-1.redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jackson-jaxrs-providers-0:2.8.11-1.redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jackson-module-jaxb-annotations-0:2.8.11-1.redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jackson-modules-java8-0:2.8.11-1.redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jboss-logmanager-0:2.0.8-1.Final_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jboss-server-migration-0:1.0.3-6.Final_redhat_6.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jbossws-cxf-0:5.1.10-1.Final_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-narayana-0:5.5.31-1.Final_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-picketlink-bindings-0:2.5.5-10.SP9_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-picketlink-federation-0:2.5.5-10.SP9_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-resteasy-0:3.0.25-1.Final_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-undertow-0:1.4.18-4.SP2_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-undertow-jastow-0:2.0.3-1.Final_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-wildfly-0:7.1.1-4.GA_redhat_2.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-wildfly-elytron-0:1.1.8-1.Final_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-wildfly-http-client-0:1.0.9-1.Final_redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-wildfly-javadocs-0:7.1.1-3.GA_redhat_2.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-wss4j-0:2.1.11-1.redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-xml-security-0:2.0.9-1.redhat_1.1.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 | RedHat | eap7-jboss-ec2-eap-0:7.1.1-3.1.GA_redhat_3.ep7.el6 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-activemq-artemis-0:1.5.5.009-1.redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-apache-cxf-0:3.1.13-1.redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-glassfish-jsf-0:2.2.13-6.SP5_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-hibernate-0:5.1.12-1.Final_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-infinispan-0:8.2.9-1.Final_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-ironjacamar-0:1.4.7-1.Final_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jackson-annotations-0:2.8.11-1.redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jackson-core-0:2.8.11-1.redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jackson-databind-0:2.8.11-1.redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jackson-jaxrs-providers-0:2.8.11-1.redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jackson-module-jaxb-annotations-0:2.8.11-1.redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jackson-modules-java8-0:2.8.11-1.redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jboss-logmanager-0:2.0.8-1.Final_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jboss-server-migration-0:1.0.3-6.Final_redhat_6.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jbossws-cxf-0:5.1.10-1.Final_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-narayana-0:5.5.31-1.Final_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-picketlink-bindings-0:2.5.5-10.SP9_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-picketlink-federation-0:2.5.5-10.SP9_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-resteasy-0:3.0.25-1.Final_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-undertow-0:1.4.18-4.SP2_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-undertow-jastow-0:2.0.3-1.Final_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-wildfly-0:7.1.1-4.GA_redhat_2.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-wildfly-elytron-0:1.1.8-1.Final_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-wildfly-http-client-0:1.0.9-1.Final_redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-wildfly-javadocs-0:7.1.1-3.GA_redhat_2.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-wss4j-0:2.1.11-1.redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-xml-security-0:2.0.9-1.redhat_1.1.ep7.el7 | * |
| Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 | RedHat | eap7-jboss-ec2-eap-0:7.1.1-3.1.GA_redhat_3.ep7.el7 | * |
| Red Hat OpenShift Container Platform 3.11 | RedHat | openshift3/ose-logging-elasticsearch5:v3.11.153-2 | * |
| Red Hat OpenShift Container Platform 4.1 | RedHat | openshift4/ose-logging-elasticsearch5:v4.1.18-201909201915 | * |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | rhvm-appliance-0:4.2-20180504.0 | * |
| Jackson-databind | Ubuntu | artful | * |
| Jackson-databind | Ubuntu | esm-apps/xenial | * |
| Jackson-databind | Ubuntu | esm-infra-legacy/trusty | * |
| Jackson-databind | Ubuntu | trusty | * |
| Jackson-databind | Ubuntu | trusty/esm | * |
| Jackson-databind | Ubuntu | upstream | * |
| Jackson-databind | Ubuntu | xenial | * |