CVE-2018-21234: Critical severity jodd vulnerability
Published May 21, 2020
·Updated
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
Affected Software
3 affected componentsFixes available
maven/org.jodd:jodd-json<5.0.4
5.0.4
Jodd Jodd<5.0.4
Apache Hive=3.1.2
Remediation
Event History
May 21, 2020
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
Description
Feb 10, 2022
Advisory Published
11:03 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-21234.
2
What is the severity of CVE-2018-21234?
The severity of CVE-2018-21234 is critical with a CVSS score of 9.8.
3
What software is affected by CVE-2018-21234?
Jodd before version 5.0.4 and Apache Hive version 3.1.2 are affected by CVE-2018-21234.
4
How does CVE-2018-21234 impact Jodd?
CVE-2018-21234 allows for Deserialization of Untrusted JSON Data when setClassMetadataName is set in Jodd before version 5.0.4.
5
How can I fix CVE-2018-21234 in Jodd?
To fix CVE-2018-21234 in Jodd, update to version 5.0.4 or later.