CVE Vulnerabilities

CVE-2018-5968

Incomplete List of Disallowed Inputs

Published: Jan 22, 2018 | Modified: Sep 13, 2023
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.1 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.

Weakness

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete, leading to resultant weaknesses.

Affected Software

Name Vendor Start Version End Version
Jackson-databind Fasterxml 2.0.0 (including) 2.6.7.3 (excluding)
Jackson-databind Fasterxml 2.7.0 (including) 2.7.9.2 (excluding)
Jackson-databind Fasterxml 2.8.0 (including) 2.8.11.1 (excluding)
Jackson-databind Fasterxml 2.9.0 (including) 2.9.4 (excluding)
Red Hat JBoss EAP 7 RedHat jackson-databind *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-activemq-artemis-0:1.5.5.009-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-apache-cxf-0:3.1.13-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-glassfish-jsf-0:2.2.13-6.SP5_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-hibernate-0:5.1.12-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-infinispan-0:8.2.9-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-ironjacamar-0:1.4.7-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jackson-annotations-0:2.8.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jackson-core-0:2.8.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jackson-databind-0:2.8.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jackson-jaxrs-providers-0:2.8.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jackson-module-jaxb-annotations-0:2.8.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jackson-modules-java8-0:2.8.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jboss-logmanager-0:2.0.8-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jboss-server-migration-0:1.0.3-6.Final_redhat_6.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jbossws-cxf-0:5.1.10-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-narayana-0:5.5.31-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-picketlink-bindings-0:2.5.5-10.SP9_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-picketlink-federation-0:2.5.5-10.SP9_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-resteasy-0:3.0.25-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-undertow-0:1.4.18-4.SP2_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-undertow-jastow-0:2.0.3-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-0:7.1.1-4.GA_redhat_2.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-elytron-0:1.1.8-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-http-client-0:1.0.9-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-javadocs-0:7.1.1-3.GA_redhat_2.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wss4j-0:2.1.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-xml-security-0:2.0.9-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jboss-ec2-eap-0:7.1.1-3.1.GA_redhat_3.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-activemq-artemis-0:1.5.5.009-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-apache-cxf-0:3.1.13-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-glassfish-jsf-0:2.2.13-6.SP5_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-hibernate-0:5.1.12-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-infinispan-0:8.2.9-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-ironjacamar-0:1.4.7-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jackson-annotations-0:2.8.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jackson-core-0:2.8.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jackson-databind-0:2.8.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jackson-jaxrs-providers-0:2.8.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jackson-module-jaxb-annotations-0:2.8.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jackson-modules-java8-0:2.8.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jboss-logmanager-0:2.0.8-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jboss-server-migration-0:1.0.3-6.Final_redhat_6.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jbossws-cxf-0:5.1.10-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-narayana-0:5.5.31-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-picketlink-bindings-0:2.5.5-10.SP9_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-picketlink-federation-0:2.5.5-10.SP9_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-resteasy-0:3.0.25-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-undertow-0:1.4.18-4.SP2_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-undertow-jastow-0:2.0.3-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-0:7.1.1-4.GA_redhat_2.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-elytron-0:1.1.8-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-http-client-0:1.0.9-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-javadocs-0:7.1.1-3.GA_redhat_2.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wss4j-0:2.1.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-xml-security-0:2.0.9-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jboss-ec2-eap-0:7.1.1-3.1.GA_redhat_3.ep7.el7 *
Red Hat OpenShift Container Platform 3.11 RedHat openshift3/ose-logging-elasticsearch5:v3.11.153-2 *
Red Hat OpenShift Container Platform 4.1 RedHat openshift4/ose-logging-elasticsearch5:v4.1.18-201909201915 *
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 RedHat rhvm-appliance-0:4.2-20180504.0 *
Jackson-databind Ubuntu artful *
Jackson-databind Ubuntu esm-apps/xenial *
Jackson-databind Ubuntu trusty *
Jackson-databind Ubuntu trusty/esm *
Jackson-databind Ubuntu upstream *
Jackson-databind Ubuntu xenial *

Potential Mitigations

References