CVE-2018-14719: Critical severity fasterxml jackson-databind vulnerability
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
Other sources
FasterXML jackson-databind 2.x before 2.9.7, 2.8.11.3, and 2.7.9.5 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.7.9.5 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.8.11.3 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.7 - Upgrade
Upgrade
debian/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.8-3+deb10u3Fixed in 2.9.8-3+deb10u5Fixed in 2.12.1-1+deb11u1Fixed in 2.14.0-1 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.7 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.7.9.5 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.8.11.3 - Upgrade
Upgrade
FasterXML jackson-databind 2.xto a version that resolves this vulnerability.Fixed in 2.9.7
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14719?
CVE-2018-14719 has a critical severity level as it allows remote attackers to execute arbitrary code.
How do I fix CVE-2018-14719?
To fix CVE-2018-14719, upgrade to jackson-databind version 2.9.7 or later, or apply the recommended versions as specified in the advisory.
What versions are affected by CVE-2018-14719?
CVE-2018-14719 affects FasterXML jackson-databind versions before 2.9.7, including 2.6.x, 2.7.x, and 2.8.x.
Can CVE-2018-14719 impact my application?
Yes, if your application uses vulnerable versions of jackson-databind, it may be susceptible to remote code execution due to this vulnerability.
Is there a workaround for CVE-2018-14719?
While upgrading is the best approach, a temporary workaround is to avoid polymorphic deserialization if feasible in your application.