Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 Maven

jackson-databind vulnerable to deserialization flaw leading to unauthenticated remote code execution

GHSA-h592-38cm-4ggp · CVE-2017-15095

Published · Modified

Description

jackson-databind in versions prior to 2.8.11 and 2.9.4 contain a deserialization flaw which allows an unauthenticated user to perform code execution by sending maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525, blacklisting additonal vulnerable classes.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes