[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2018-12023":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T14:55:33.319Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":24,"aliases":25,"duplicate_of":9,"upstream":27,"downstream":28,"duplicates":45,"related":46,"reserved_at":9,"published_at":49,"modified_at":50,"state":51,"summary":52,"references_raw":61,"kevs":267,"epss":268,"epss_history":271,"metrics":530,"affected":543},"CVE-2018-12023","An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-502","Deserialization of Untrusted Data","The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.","weakness","Draft","Base","Medium",[20],{"id":21,"name":22,"techniques":23},"CAPEC-586","Object Injection",[],[],[26],"GHSA-6wqp-v4v6-c87c",[],[29,31,33,35,37,39,41,43],{"_key":30},"UBUNTU-CVE-2018-12023",{"_key":32},"DLA-1703-1",{"_key":34},"DSA-4452-1",{"_key":36},"DEBIAN-CVE-2018-12023",{"_key":38},"RHSA-2019:0782",{"_key":40},"RHSA-2019:1107",{"_key":42},"RHSA-2019:1108",{"_key":44},"USN-4813-1",[],[47],{"_key":48},"CGA-QMMG-V87Q-5M42","2019-03-17T17:57:52.000Z","2024-08-05T08:24:03.746Z","Modified",{"cisa_kev":53,"cisa_ransomware":53,"cisa_vendor":9,"epss_severity":54,"epss_score":55,"severity":56,"severity_score":57,"severity_version":58,"severity_source":59,"severity_vector":60,"severity_status":51},false,"low",0.04938,"high",7.5,"v3.0","nvd","CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",[62,72,76,80,84,88,92,96,101,107,111,115,119,123,127,131,136,140,144,148,152,156,160,164,168,173,177,183,187,191,195,199,204,209,213,217,221,225,230,234,238,242,246,250,254,258,262],{"url":63,"sources":64,"tags":67},"https://access.redhat.com/errata/RHSA-2019:0782",[65,59,66],"cve.org","osv_maven",[68,69,70,71],"Vendor Advisory","X Refsource REDHAT","Third Party Advisory","WEB",{"url":73,"sources":74,"tags":75},"https://access.redhat.com/errata/RHSA-2019:0877",[65,59,66],[68,69,70,71],{"url":77,"sources":78,"tags":79},"https://access.redhat.com/errata/RHBA-2019:0959",[65,59,66],[68,69,70,71],{"url":81,"sources":82,"tags":83},"https://access.redhat.com/errata/RHSA-2019:1107",[65,59,66],[68,69,70,71],{"url":85,"sources":86,"tags":87},"https://access.redhat.com/errata/RHSA-2019:1108",[65,59,66],[68,69,70,71],{"url":89,"sources":90,"tags":91},"https://access.redhat.com/errata/RHSA-2019:1106",[65,59,66],[68,69,70,71],{"url":93,"sources":94,"tags":95},"https://access.redhat.com/errata/RHSA-2019:1140",[65,59,66],[68,69,70,71],{"url":97,"sources":98,"tags":99},"https://www.debian.org/security/2019/dsa-4452",[65,59,66],[68,100,70,71],"X Refsource DEBIAN",{"url":102,"sources":103,"tags":104},"https://seclists.org/bugtraq/2019/May/68",[65,59,66],[105,106,70,71],"Mailing List","X Refsource BUGTRAQ",{"url":108,"sources":109,"tags":110},"https://access.redhat.com/errata/RHSA-2019:1782",[65,59,66],[68,69,70,71],{"url":112,"sources":113,"tags":114},"https://access.redhat.com/errata/RHSA-2019:1797",[65,59,66],[68,69,70,71],{"url":116,"sources":117,"tags":118},"https://access.redhat.com/errata/RHSA-2019:1822",[65,59,66],[68,69,70,71],{"url":120,"sources":121,"tags":122},"https://access.redhat.com/errata/RHSA-2019:1823",[65,59,66],[68,69,70,71],{"url":124,"sources":125,"tags":126},"https://access.redhat.com/errata/RHSA-2019:2804",[65,59,66],[68,69,71],{"url":128,"sources":129,"tags":130},"https://access.redhat.com/errata/RHSA-2019:2858",[65,59,66],[68,69,71],{"url":132,"sources":133,"tags":134},"https://lists.apache.org/thread.html/7fcf88aff0d1deaa5c3c7be8d58c05ad7ad5da94b59065d8e7c50c5d%40%3Cissues.lucene.apache.org%3E",[65,59],[105,135],"X Refsource MLIST",{"url":137,"sources":138,"tags":139},"https://access.redhat.com/errata/RHSA-2019:3002",[65,59,66],[68,69,71],{"url":141,"sources":142,"tags":143},"https://access.redhat.com/errata/RHSA-2019:3140",[65,59,66],[68,69,71],{"url":145,"sources":146,"tags":147},"https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E",[65,59],[105,135],{"url":149,"sources":150,"tags":151},"https://access.redhat.com/errata/RHSA-2019:3149",[65,59,66],[68,69,71],{"url":153,"sources":154,"tags":155},"https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E",[65,59],[105,135],{"url":157,"sources":158,"tags":159},"https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E",[65,59],[105,135],{"url":161,"sources":162,"tags":163},"https://access.redhat.com/errata/RHSA-2019:3892",[65,59,66],[68,69,71],{"url":165,"sources":166,"tags":167},"https://access.redhat.com/errata/RHSA-2019:4037",[65,59,66],[68,69,71],{"url":169,"sources":170,"tags":171},"https://www.oracle.com/security-alerts/cpuapr2020.html",[65,59,66],[172,71],"X Refsource MISC",{"url":174,"sources":175,"tags":176},"https://www.oracle.com/security-alerts/cpujul2020.html",[65,59,66],[172,71],{"url":178,"sources":179,"tags":180},"https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html",[65,59,66],[181,182,70,71],"X Refsource CONFIRM","Patch",{"url":184,"sources":185,"tags":186},"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html",[65,59,66],[172,182,70,71],{"url":188,"sources":189,"tags":190},"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html",[65,59,66],[172,182,70,71],{"url":192,"sources":193,"tags":194},"https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html",[65,59,66],[181,182,70,71],{"url":196,"sources":197,"tags":198},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZEDLDUYBSTDY4GWDBUXGJNS2RFYTFVRC/",[65,59],[172],{"url":200,"sources":201,"tags":202},"https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf",[65,59,66],[172,203,70,71],"Technical Description",{"url":205,"sources":206,"tags":207},"http://www.securityfocus.com/bid/105659",[65,59,66],[172,70,208,71],"VDB Entry",{"url":210,"sources":211,"tags":212},"https://github.com/FasterXML/jackson-databind/issues/2058",[65,59,66],[172,182,70,71],{"url":214,"sources":215,"tags":216},"https://github.com/FasterXML/jackson-databind/commit/28badf7ef60ac3e7ef151cd8e8ec010b8479226a",[65,59,66],[172,182,70,71],{"url":218,"sources":219,"tags":220},"https://security.netapp.com/advisory/ntap-20190530-0003/",[65,59],[181,70],{"url":222,"sources":223,"tags":224},"https://www.oracle.com/security-alerts/cpuoct2020.html",[65,59,66],[172,71],{"url":226,"sources":227,"tags":228},"https://nvd.nist.gov/vuln/detail/CVE-2018-12023",[66],[229],"Advisory",{"url":231,"sources":232,"tags":233},"https://github.com/FasterXML/jackson-databind/commit/7487cf7eb14be2f65a1eb108e8629c07ef45e0a",[66],[71],{"url":235,"sources":236,"tags":237},"https://github.com/FasterXML/jackson-databind/commit/bf261d404c2f79fd3406237710d40ebb03c99d84",[66],[71],{"url":239,"sources":240,"tags":241},"https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E",[66],[71],{"url":243,"sources":244,"tags":245},"https://lists.apache.org/thread.html/7fcf88aff0d1deaa5c3c7be8d58c05ad7ad5da94b59065d8e7c50c5d@%3Cissues.lucene.apache.org%3E",[66],[71],{"url":247,"sources":248,"tags":249},"https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E",[66],[71],{"url":251,"sources":252,"tags":253},"https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E",[66],[71],{"url":255,"sources":256,"tags":257},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZEDLDUYBSTDY4GWDBUXGJNS2RFYTFVRC",[66],[71],{"url":259,"sources":260,"tags":261},"https://security.netapp.com/advisory/ntap-20190530-0003",[66],[71],{"url":263,"sources":264,"tags":265},"https://github.com/FasterXML/jackson-databind",[66],[266],"PACKAGE",[],{"date":269,"score":55,"percentile":270},"2026-06-04",0.89807,[272,276,279,282,284,287,290,293,295,298,301,304,307,310,313,317,320,323,326,328,331,334,337,340,342,345,348,351,354,357,359,361,364,366,369,371,374,377,380,383,386,388,391,393,396,400,403,406,409,412,415,418,421,424,427,430,432,435,439,442,445,448,450,453,456,459,462,465,468,471,474,477,480,482,485,488,491,494,497,499,502,505,508,511,514,517,519,522,525,527],{"date":273,"score":274,"percentile":275},"2025-11-04",0.04655,0.88801,{"date":277,"score":274,"percentile":278},"2025-11-05",0.888,{"date":280,"score":274,"percentile":281},"2025-11-06",0.88792,{"date":283,"score":274,"percentile":278},"2025-11-07",{"date":285,"score":274,"percentile":286},"2025-11-08",0.88802,{"date":288,"score":274,"percentile":289},"2025-11-09",0.88799,{"date":291,"score":274,"percentile":292},"2025-11-10",0.88795,{"date":294,"score":274,"percentile":289},"2025-11-11",{"date":296,"score":274,"percentile":297},"2025-11-12",0.88806,{"date":299,"score":274,"percentile":300},"2025-11-13",0.8881,{"date":302,"score":274,"percentile":303},"2025-11-14",0.88815,{"date":305,"score":274,"percentile":306},"2025-11-15",0.88811,{"date":308,"score":274,"percentile":309},"2025-11-16",0.88814,{"date":311,"score":274,"percentile":312},"2025-11-17",0.88809,{"date":314,"score":315,"percentile":316},"2025-11-18",0.02262,0.83254,{"date":318,"score":315,"percentile":319},"2025-11-19",0.83256,{"date":321,"score":315,"percentile":322},"2025-11-20",0.83262,{"date":324,"score":274,"percentile":325},"2025-11-21",0.88826,{"date":327,"score":274,"percentile":325},"2025-11-22",{"date":329,"score":274,"percentile":330},"2025-11-23",0.88822,{"date":332,"score":274,"percentile":333},"2025-11-24",0.88823,{"date":335,"score":274,"percentile":336},"2025-11-25",0.88827,{"date":338,"score":274,"percentile":339},"2025-11-26",0.88825,{"date":341,"score":274,"percentile":336},"2025-11-27",{"date":343,"score":274,"percentile":344},"2025-11-28",0.8882,{"date":346,"score":274,"percentile":347},"2025-11-29",0.88891,{"date":349,"score":274,"percentile":350},"2025-11-30",0.88886,{"date":352,"score":274,"percentile":353},"2025-12-01",0.88945,{"date":355,"score":274,"percentile":356},"2025-12-02",0.88947,{"date":358,"score":274,"percentile":353},"2025-12-03",{"date":360,"score":274,"percentile":350},"2025-12-04",{"date":362,"score":274,"percentile":363},"2025-12-05",0.88885,{"date":365,"score":274,"percentile":363},"2025-12-06",{"date":367,"score":274,"percentile":368},"2025-12-07",0.88884,{"date":370,"score":274,"percentile":363},"2025-12-08",{"date":372,"score":274,"percentile":373},"2025-12-09",0.88892,{"date":375,"score":274,"percentile":376},"2025-12-10",0.88911,{"date":378,"score":274,"percentile":379},"2025-12-11",0.88912,{"date":381,"score":274,"percentile":382},"2025-12-12",0.88916,{"date":384,"score":274,"percentile":385},"2025-12-13",0.88917,{"date":387,"score":274,"percentile":385},"2025-12-14",{"date":389,"score":274,"percentile":390},"2025-12-15",0.88919,{"date":392,"score":274,"percentile":390},"2025-12-16",{"date":394,"score":274,"percentile":395},"2025-12-17",0.88922,{"date":397,"score":398,"percentile":399},"2025-12-18",0.049,0.89232,{"date":401,"score":398,"percentile":402},"2025-12-19",0.89233,{"date":404,"score":398,"percentile":405},"2025-12-20",0.89231,{"date":407,"score":398,"percentile":408},"2025-12-21",0.8924,{"date":410,"score":398,"percentile":411},"2025-12-22",0.89241,{"date":413,"score":398,"percentile":414},"2025-12-23",0.89243,{"date":416,"score":398,"percentile":417},"2025-12-24",0.89249,{"date":419,"score":398,"percentile":420},"2025-12-25",0.8926,{"date":422,"score":398,"percentile":423},"2025-12-26",0.89257,{"date":425,"score":398,"percentile":426},"2025-12-27",0.89307,{"date":428,"score":398,"percentile":429},"2025-12-28",0.89252,{"date":431,"score":398,"percentile":417},"2025-12-29",{"date":433,"score":398,"percentile":434},"2025-12-30",0.89255,{"date":436,"score":437,"percentile":438},"2025-12-31",0.04812,0.89155,{"date":440,"score":437,"percentile":441},"2026-01-01",0.89224,{"date":443,"score":437,"percentile":444},"2026-01-02",0.89219,{"date":446,"score":437,"percentile":447},"2026-01-03",0.89217,{"date":449,"score":437,"percentile":438},"2026-01-04",{"date":451,"score":437,"percentile":452},"2026-01-05",0.89154,{"date":454,"score":437,"percentile":455},"2026-01-06",0.89159,{"date":457,"score":437,"percentile":458},"2026-01-07",0.89161,{"date":460,"score":437,"percentile":461},"2026-01-08",0.89167,{"date":463,"score":437,"percentile":464},"2026-01-09",0.89171,{"date":466,"score":437,"percentile":467},"2026-01-10",0.89172,{"date":469,"score":437,"percentile":470},"2026-01-11",0.89165,{"date":472,"score":437,"percentile":473},"2026-01-12",0.89163,{"date":475,"score":437,"percentile":476},"2026-01-13",0.8916,{"date":478,"score":437,"percentile":479},"2026-01-14",0.89175,{"date":481,"score":437,"percentile":479},"2026-01-15",{"date":483,"score":437,"percentile":484},"2026-01-16",0.8918,{"date":486,"score":437,"percentile":487},"2026-01-17",0.89183,{"date":489,"score":437,"percentile":490},"2026-01-18",0.89181,{"date":492,"score":437,"percentile":493},"2026-01-19",0.89177,{"date":495,"score":437,"percentile":496},"2026-01-20",0.89179,{"date":498,"score":437,"percentile":487},"2026-01-21",{"date":500,"score":437,"percentile":501},"2026-01-22",0.89188,{"date":503,"score":437,"percentile":504},"2026-01-23",0.89202,{"date":506,"score":437,"percentile":507},"2026-01-24",0.89209,{"date":509,"score":437,"percentile":510},"2026-01-25",0.8921,{"date":512,"score":437,"percentile":513},"2026-01-26",0.89208,{"date":515,"score":437,"percentile":516},"2026-01-27",0.89206,{"date":518,"score":437,"percentile":510},"2026-01-28",{"date":520,"score":437,"percentile":521},"2026-01-29",0.89213,{"date":523,"score":437,"percentile":524},"2026-01-30",0.89214,{"date":526,"score":437,"percentile":521},"2026-01-31",{"date":528,"score":437,"percentile":529},"2026-02-01",0.89279,[531,541],{"source":59,"cvss_v2_0":532,"cvss_v3_0":537,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":533,"baseSeverity":9,"vectorString":534,"impactScore":535,"exploitabilityScore":536},5.1,"AV:N/AC:H/Au:N/C:P/I:P/A:P",6.4,4.9,{"baseScore":57,"baseSeverity":538,"vectorString":60,"impactScore":539,"exploitabilityScore":540},"HIGH",9.8,4.1,{"source":66,"cvss_v2_0":9,"cvss_v3_0":542,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":57,"baseSeverity":9,"vectorString":60,"impactScore":539,"exploitabilityScore":540},[544,553,573,579,592,599,605,612,617,623,629,635],{"ecosystem":9,"name":545,"vendor":546,"product":547,"cpe_part":548,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":549},"debian linux","debian","debian_linux","o",[550],{"version":551,"is_range":53,"range_type":552,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"9.0","cpe",{"ecosystem":9,"name":554,"vendor":555,"product":554,"cpe_part":556,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":557},"jackson-databind","fasterxml","a",[558,565,569],{"version":559,"is_range":560,"range_type":552,"version_start":561,"version_start_type":562,"version_end":563,"version_end_type":564,"fixed_in":9},"gte2.7.0_lt2.7.9.4",true,"2.7.0","including","2.7.9.4","excluding",{"version":566,"is_range":560,"range_type":552,"version_start":567,"version_start_type":562,"version_end":568,"version_end_type":564,"fixed_in":9},"gte2.8.0_lt2.8.11.2","2.8.0","2.8.11.2",{"version":570,"is_range":560,"range_type":552,"version_start":571,"version_start_type":562,"version_end":572,"version_end_type":564,"fixed_in":9},"gte2.9.0_lt2.9.6","2.9.0","2.9.6",{"ecosystem":9,"name":574,"vendor":575,"product":574,"cpe_part":548,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":576},"fedora","fedoraproject",[577],{"version":578,"is_range":53,"range_type":552,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"29",{"ecosystem":580,"name":581,"vendor":582,"product":554,"cpe_part":9,"purl_type":583,"purl_namespace":582,"purl_name":554,"source":9,"versions":584},"Maven","com.fasterxml.jackson.core:jackson-databind","com.fasterxml.jackson.core","maven",[585,588,590],{"version":586,"is_range":560,"range_type":587,"version_start":561,"version_start_type":562,"version_end":563,"version_end_type":564,"fixed_in":9},"gte2_7_0_lt2_7_9_4","ecosystem",{"version":589,"is_range":560,"range_type":587,"version_start":567,"version_start_type":562,"version_end":568,"version_end_type":564,"fixed_in":9},"gte2_8_0_lt2_8_11_2",{"version":591,"is_range":560,"range_type":587,"version_start":571,"version_start_type":562,"version_end":572,"version_end_type":564,"fixed_in":9},"gte2_9_0_lt2_9_6",{"ecosystem":9,"name":593,"vendor":594,"product":595,"cpe_part":556,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":596},"jd edwards enterpriseone tools","oracle","jd_edwards_enterpriseone_tools",[597],{"version":598,"is_range":53,"range_type":552,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"9.2",{"ecosystem":9,"name":600,"vendor":594,"product":601,"cpe_part":556,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":602},"retail merchandising system","retail_merchandising_system",[603],{"version":604,"is_range":53,"range_type":552,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"15.0",{"ecosystem":9,"name":606,"vendor":607,"product":608,"cpe_part":556,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":609},"automation manager","redhat","automation_manager",[610],{"version":611,"is_range":53,"range_type":552,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.3.1",{"ecosystem":9,"name":613,"vendor":607,"product":614,"cpe_part":556,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":615},"decision manager","decision_manager",[616],{"version":611,"is_range":53,"range_type":552,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"ecosystem":9,"name":618,"vendor":607,"product":619,"cpe_part":556,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":620},"jboss brms","jboss_brms",[621],{"version":622,"is_range":53,"range_type":552,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.4.10",{"ecosystem":9,"name":624,"vendor":607,"product":625,"cpe_part":556,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":626},"jboss enterprise application platform","jboss_enterprise_application_platform",[627],{"version":628,"is_range":53,"range_type":552,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.2.0",{"ecosystem":9,"name":630,"vendor":607,"product":631,"cpe_part":556,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":632},"openshift container platform","openshift_container_platform",[633],{"version":634,"is_range":53,"range_type":552,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"3.11",{"ecosystem":9,"name":636,"vendor":607,"product":637,"cpe_part":556,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":638},"single sign-on","single_sign-on",[639],{"version":640,"is_range":53,"range_type":552,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.3"]