CVE-2018-19361: Critical severity fasterxml jackson-databind vulnerability
FasterXML jackson-databind 2.x before 2.9.8 fails to block the openjpa class from polymorphic deserialization.
References: https://github.com/FasterXML/jackson-databind/issues/2186 https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8
Upstream Patch: https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b
Other sources
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.8-3+deb10u3Fixed in 2.9.8-3+deb10u5Fixed in 2.12.1-1+deb11u1Fixed in 2.14.0-1 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.8 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.7.9.5 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.8.11.3 - Upgrade
Upgrade
FasterXML jackson-databind 2.xto a version that resolves this vulnerability.Fixed in 2.9.8Patch 42912cac4753f3f718ece875e4d486f8264c2f2b
Event History
Frequently Asked Questions
What is CVE-2018-19361?
CVE-2018-19361 is an unspecified error with failure to block the openjpa class from polymorphic deserialization in FasterXML jackson-databind before version 2.9.8.
How does CVE-2018-19361 impact the system?
CVE-2018-19361 may allow attackers to have an unspecified impact by leveraging the failure to block the openjpa class from polymorphic deserialization.
What is the severity of CVE-2018-19361?
CVE-2018-19361 has a severity score of 5.3 (High).
Which software versions are affected by CVE-2018-19361?
CVE-2018-19361 affects FasterXML jackson-databind versions 2.9.7 and earlier.
How can CVE-2018-19361 be fixed?
To fix CVE-2018-19361, upgrade to FasterXML jackson-databind version 2.9.8 or later.