CVE-2018-14718: Critical severity fasterxml jackson-databind vulnerability
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
Other sources
FasterXML jackson-databind 2.x before 2.9.7, 2.8.11.3, 2.7.9.5, and 2.6.7.3 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.6.7.3 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.7.9.5 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.8.11.3 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.7 - Upgrade
Upgrade
debian/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.8-3+deb10u3Fixed in 2.9.8-3+deb10u5Fixed in 2.12.1-1+deb11u1Fixed in 2.14.0-1 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.7 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.7.9.5 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.8.11.3 - Upgrade
Upgrade
FasterXML jackson-databind 2.xto a version that resolves this vulnerability.Fixed in 2.9.7 - Upgrade
Upgrade
FasterXML jackson-databind 2.8.xto a version that resolves this vulnerability.Fixed in 2.8.11.3 - Upgrade
Upgrade
FasterXML jackson-databind 2.7.xto a version that resolves this vulnerability.Fixed in 2.7.9.5 - Upgrade
Upgrade
FasterXML jackson-databind 2.6.xto a version that resolves this vulnerability.Fixed in 2.6.7.3
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14718?
CVE-2018-14718 is classified as critical due to its potential for remote code execution.
How do I fix CVE-2018-14718?
To mitigate CVE-2018-14718, upgrade jackson-databind to version 2.9.7 or later.
Which versions of jackson-databind are affected by CVE-2018-14718?
Versions of jackson-databind below 2.9.7, specifically all versions from 2.0.0 to 2.9.6, are vulnerable to CVE-2018-14718.
Is my software vulnerable if I use Jackson version 2.8.11?
Yes, Jackson version 2.8.11 is vulnerable to CVE-2018-14718; you must upgrade to at least version 2.8.11.3.
Can CVE-2018-14718 affect my web application?
Yes, if your web application uses a vulnerable version of jackson-databind, it can be exploited to execute arbitrary code.