FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete, leading to resultant weaknesses.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jackson-databind | Fasterxml | 2.0.0 (including) | 2.6.7.3 (excluding) |
Jackson-databind | Fasterxml | 2.7.0 (including) | 2.7.9.2 (excluding) |
Jackson-databind | Fasterxml | 2.8.0 (including) | 2.8.11.1 (excluding) |
Jackson-databind | Fasterxml | 2.9.0 (including) | 2.9.4 (excluding) |