CVE-2017-17485
CRITICAL severity · CVSS 9.8 · Insecure deserialization
9.8CVSS CRITICAL
Summary
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredNone
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)50%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://www.securityfocus.com/archive/1/541652/100/0/threadedAdvisory
- https://access.redhat.com/errata/RHSA-2018:0116Advisory
- https://access.redhat.com/errata/RHSA-2018:0342Advisory
- https://access.redhat.com/errata/RHSA-2018:0478Advisory
- https://access.redhat.com/errata/RHSA-2018:0479Advisory
- https://access.redhat.com/errata/RHSA-2018:0480Advisory
- https://access.redhat.com/errata/RHSA-2018:0481Advisory
- https://access.redhat.com/errata/RHSA-2018:1447Advisory