CVE Vulnerabilities

CVE-2018-5968

Incomplete List of Disallowed Inputs

Published: Jan 22, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.1 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.

Weakness

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Affected Software

NameVendorStart VersionEnd Version
Jackson-databindFasterxml2.0.0 (including)2.6.7.3 (excluding)
Jackson-databindFasterxml2.7.0 (including)2.7.9.2 (excluding)
Jackson-databindFasterxml2.8.0 (including)2.8.11.1 (excluding)
Jackson-databindFasterxml2.9.0 (including)2.9.4 (excluding)
Red Hat JBoss EAP 7RedHatjackson-databind*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-activemq-artemis-0:1.5.5.009-1.redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-apache-cxf-0:3.1.13-1.redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-glassfish-jsf-0:2.2.13-6.SP5_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-hibernate-0:5.1.12-1.Final_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-infinispan-0:8.2.9-1.Final_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-ironjacamar-0:1.4.7-1.Final_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jackson-annotations-0:2.8.11-1.redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jackson-core-0:2.8.11-1.redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jackson-databind-0:2.8.11-1.redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jackson-jaxrs-providers-0:2.8.11-1.redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jackson-module-jaxb-annotations-0:2.8.11-1.redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jackson-modules-java8-0:2.8.11-1.redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jboss-logmanager-0:2.0.8-1.Final_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jboss-server-migration-0:1.0.3-6.Final_redhat_6.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jbossws-cxf-0:5.1.10-1.Final_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-narayana-0:5.5.31-1.Final_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-picketlink-bindings-0:2.5.5-10.SP9_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-picketlink-federation-0:2.5.5-10.SP9_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-resteasy-0:3.0.25-1.Final_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-undertow-0:1.4.18-4.SP2_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-undertow-jastow-0:2.0.3-1.Final_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-wildfly-0:7.1.1-4.GA_redhat_2.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-wildfly-elytron-0:1.1.8-1.Final_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-wildfly-http-client-0:1.0.9-1.Final_redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-wildfly-javadocs-0:7.1.1-3.GA_redhat_2.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-wss4j-0:2.1.11-1.redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-xml-security-0:2.0.9-1.redhat_1.1.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6RedHateap7-jboss-ec2-eap-0:7.1.1-3.1.GA_redhat_3.ep7.el6*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-activemq-artemis-0:1.5.5.009-1.redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-apache-cxf-0:3.1.13-1.redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-glassfish-jsf-0:2.2.13-6.SP5_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-hibernate-0:5.1.12-1.Final_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-infinispan-0:8.2.9-1.Final_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-ironjacamar-0:1.4.7-1.Final_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jackson-annotations-0:2.8.11-1.redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jackson-core-0:2.8.11-1.redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jackson-databind-0:2.8.11-1.redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jackson-jaxrs-providers-0:2.8.11-1.redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jackson-module-jaxb-annotations-0:2.8.11-1.redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jackson-modules-java8-0:2.8.11-1.redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jboss-logmanager-0:2.0.8-1.Final_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jboss-server-migration-0:1.0.3-6.Final_redhat_6.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jbossws-cxf-0:5.1.10-1.Final_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-narayana-0:5.5.31-1.Final_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-picketlink-bindings-0:2.5.5-10.SP9_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-picketlink-federation-0:2.5.5-10.SP9_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-resteasy-0:3.0.25-1.Final_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-undertow-0:1.4.18-4.SP2_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-undertow-jastow-0:2.0.3-1.Final_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-wildfly-0:7.1.1-4.GA_redhat_2.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-wildfly-elytron-0:1.1.8-1.Final_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-wildfly-http-client-0:1.0.9-1.Final_redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-wildfly-javadocs-0:7.1.1-3.GA_redhat_2.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-wss4j-0:2.1.11-1.redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-xml-security-0:2.0.9-1.redhat_1.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7RedHateap7-jboss-ec2-eap-0:7.1.1-3.1.GA_redhat_3.ep7.el7*
Red Hat OpenShift Container Platform 3.11RedHatopenshift3/ose-logging-elasticsearch5:v3.11.153-2*
Red Hat OpenShift Container Platform 4.1RedHatopenshift4/ose-logging-elasticsearch5:v4.1.18-201909201915*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatrhvm-appliance-0:4.2-20180504.0*
Jackson-databindUbuntuartful*
Jackson-databindUbuntuesm-apps/xenial*
Jackson-databindUbuntuesm-infra-legacy/trusty*
Jackson-databindUbuntutrusty*
Jackson-databindUbuntutrusty/esm*
Jackson-databindUbuntuupstream*
Jackson-databindUbuntuxenial*

Potential Mitigations

References