CVE-2018-19362: Critical severity fasterxml jackson-databind vulnerability
FasterXML jackson-databind 2.x before 2.9.8 fails to block the jboss-common-core class from polymorphic deserialization.
References: https://github.com/FasterXML/jackson-databind/issues/2186 https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8
Upstream Patch: https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b
Other sources
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.8-3+deb10u3Fixed in 2.9.8-3+deb10u5Fixed in 2.12.1-1+deb11u1Fixed in 2.14.0-1 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.6.7.3 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.7.9.5 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.8.11.3 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.8 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.9.8 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.7.9.5 - Upgrade
Upgrade
redhat/jackson-databindto a version that resolves this vulnerability.Fixed in 2.8.11.3 - Upgrade
Upgrade
FasterXML jackson-databind 2.xto a version that resolves this vulnerability.Fixed in 2.9.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 42912cac4753f3f718ece875e4d486f8264c2f2b
Event History
Frequently Asked Questions
What is CVE-2018-19362?
CVE-2018-19362 is an unspecified error with failure to block the jboss-common-core class from polymorphic deserialization in FasterXML jackson-databind before version 2.9.8.
How does CVE-2018-19362 impact the affected software?
CVE-2018-19362 might allow attackers to have unspecified impact on the affected software by leveraging the failure to block the jboss-common-core class from polymorphic deserialization in FasterXML jackson-databind.
Is there a specific version of jackson-databind affected by CVE-2018-19362?
Yes, the affected versions of jackson-databind are 2.7.9.5, 2.8.11.3, and versions prior to 2.9.8.
What is the severity of CVE-2018-19362?
CVE-2018-19362 has a severity level of 5.3 (high).
How do I fix CVE-2018-19362?
To fix CVE-2018-19362, update your installation of FasterXML jackson-databind to version 2.9.8 or higher.