You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CVE ID:CVE-2018-12022 Description: An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload. CVSS Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P
CVE ID: CVE-2018-12022
Description: An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.
CVSS Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P
CVSS Score: 5.1
Exploitability score: 4.9Impact score: 6.4
Discovery Date: 2019-05-30
Vendors:
References:
* [RHSA-2019:1106](https://access.redhat.com/errata/RHSA-2019:1106) * [RHSA-2019:0877](https://access.redhat.com/errata/RHSA-2019:0877) * [https://github.com/FasterXML/jackson-databind/issues/2052](https://github.com/FasterXML/jackson-databind/issues/2052) * [https://bugzilla.redhat.com/show_bug.cgi?id=1671098](https://bugzilla.redhat.com/show_bug.cgi?id=1671098) * [RHSA-2019:1108](https://access.redhat.com/errata/RHSA-2019:1108) * [https://security.netapp.com/advisory/ntap-20190530-0003/](https://security.netapp.com/advisory/ntap-20190530-0003/) * [https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf](https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf) * [https://lists.fedoraproject.org/archives/list/[email protected]/message/ZEDLDUYBSTDY4GWDBUXGJNS2RFYTFVRC/](https://lists.fedoraproject.org/archives/list/[email protected]/message/ZEDLDUYBSTDY4GWDBUXGJNS2RFYTFVRC/) * [RHSA-2019:1140](https://access.redhat.com/errata/RHSA-2019:1140) * [RHBA-2019:0959](https://access.redhat.com/errata/RHBA-2019:0959) * [RHSA-2019:1107](https://access.redhat.com/errata/RHSA-2019:1107) * [DSA-4452](https://www.debian.org/security/2019/dsa-4452) * [https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062](https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062) * [https://github.com/FasterXML/jackson-databind/commit/28badf7ef60ac3e7ef151cd8e8ec010b8479226a](https://github.com/FasterXML/jackson-databind/commit/28badf7ef60ac3e7ef151cd8e8ec010b8479226a) * [https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html](https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html) * [20190527 [SECURITY] [DSA 4452-1] jackson-databind security update](https://seclists.org/bugtraq/2019/May/68) * [RHSA-2019:0782](https://access.redhat.com/errata/RHSA-2019:0782)The text was updated successfully, but these errors were encountered: