Candidate: CVE-2017-17485 PublicDate: 2018-01-10 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17485 https://bugzilla.redhat.com/show_bug.cgi?id=1528565#c0 Description: FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath. Ubuntu-Description: It was discovered that Jackson Databind incorrectly handled deserialization. An attacker could possibly use this issue to execute arbitrary code. Notes: msalvatore> The fix for CVE-2017-7525 has not yet been applied Bugs: Priority: high Discovered-by: Changfeng Chi Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_jackson-databind: upstream_jackson-databind: released (2.9.4-1) precise/esm_jackson-databind: DNE trusty_jackson-databind: ignored (reached end-of-life) trusty/esm_jackson-databind: DNE (trusty was needed) xenial_jackson-databind: ignored (end of standard support, was needed) zesty_jackson-databind: ignored (reached end-of-life) artful_jackson-databind: ignored (reached end-of-life) bionic_jackson-databind: not-affected (2.9.4-1) cosmic_jackson-databind: not-affected (2.9.4-1) disco_jackson-databind: not-affected (2.9.4-1) eoan_jackson-databind: not-affected (2.9.4-1) focal_jackson-databind: not-affected (2.9.4-1) groovy_jackson-databind: not-affected (2.9.4-1) hirsute_jackson-databind: not-affected (2.9.4-1) impish_jackson-databind: not-affected (2.9.4-1) jammy_jackson-databind: not-affected (2.9.4-1) devel_jackson-databind: not-affected (2.9.4-1)