CVE-2018-5968

Aliases:GHSA-w3f4-3q6j-rh82DEBIAN-CVE-2018-5968CGA-2mhr-2858-7rcrCGA-2p5h-94qv-433gCGA-2w6q-9cjp-c4vvCGA-482w-q892-3mvjCGA-4wh4-23x6-p926CGA-58fw-592m-37vrCGA-64h2-2g84-m7h2CGA-6cx7-2vgq-qr6rCGA-7gv3-hjrh-mpvgCGA-8wjw-mm3g-p48pCGA-99c5-72p5-544vCGA-9p33-7v98-8frrCGA-c5xg-vcgj-mv5pCGA-fjjm-hwvx-ggr7CGA-g8qv-f7g7-x69wCGA-g9r7-c3vh-82vxCGA-gppc-c6xq-phvvCGA-hg76-f95h-c7prCGA-m9pv-qgm3-jpq5CGA-pf6p-f9f7-jvcfCGA-qjmg-27j9-4j2jCGA-qw8r-x698-395pCGA-r79c-jww5-wj29CGA-rf3f-p464-p58qCGA-rwr7-6mf7-fcf2CGA-vx67-74xm-mm7rCGA-2h38-c5xq-rgwhCGA-43r4-5f9w-v5gpCGA-525v-36v3-3c4fCGA-7pwh-f545-4f36CGA-7rg2-ppv2-679fCGA-963g-jgv8-w87cCGA-c2h6-q2v7-g2fxCGA-fqjv-9jrx-66jrCGA-hphv-px69-j2p6CGA-j4cc-v7x5-6vqhCGA-j9c5-pvh2-5jfhCGA-m246-chgj-ppghCGA-qgpc-vj46-hc5fCGA-r9qv-9mgh-6qxhCGA-xpcg-4m4q-44f5CGA-2mf6-98rp-rmfmCGA-2pvh-94fx-4wxwCGA-3788-56q6-cjq8CGA-5734-x2h7-q7rhCGA-5crf-348c-pmxcCGA-5g92-7gx5-mh8wCGA-72h5-764m-3qr5CGA-73wm-c84c-r9fqCGA-7842-96ww-2cxjCGA-7fg4-pxrc-g69cCGA-cp62-472j-75f6CGA-gvcg-8jvr-jgh9CGA-h5rr-c36j-6vrjCGA-pq48-xppx-pxmwCGA-vxp4-p2r4-j255CGA-x6q9-897r-xw5xCGA-x83c-96xm-mr98CGA-xp7v-c8ph-qj4mCGA-2954-4xwq-76v7CGA-2pvw-43h9-jhc8CGA-36xq-x6hp-rj6xCGA-4j56-rpv3-3p8cCGA-5fmm-gf3p-rp4pCGA-66mp-88cg-gpj3CGA-6v9r-g5h7-2cxfCGA-7hx3-m3cc-q565CGA-9pj9-3mcv-mq4jCGA-c8m8-gmg5-qwh3CGA-gmpj-r2m7-ffpgCGA-j7jc-gqxx-cmx7CGA-mrmh-vj9f-jv4wCGA-p8jc-6wjr-vwx3CGA-q992-wfq9-ghx8CGA-x49x-g9hc-qv3pCGA-x7g3-6fpq-w9p3
Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 22 Jan 2018, 04:00
Last modified:05 Aug 2024, 05:47

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
8.1 HIGH
v3.1 (nvd)
EPSS Score
6.99% LOW
7% probability +5.25%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

22 Jan 2018, 04:00
Published
Vulnerability first disclosed
05 Aug 2024, 05:47
Last Modified
Vulnerability information updated

Description

FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 6.99% Percentile: 94%

Techniques & Countermeasures

  • CWE-184Incomplete List of Disallowed Inputs

    The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • chainguardeco-java-gradle-2.10

    all

  • chainguardeco-java-gradle-2.11

    all

  • chainguardeco-java-gradle-2.12

    all

  • chainguardeco-java-gradle-2.13

    all

  • chainguardeco-java-gradle-2.14

    all

  • chainguardeco-java-gradle-2.14.1

    all

  • chainguardeco-java-gradle-2.4

    all

  • chainguardeco-java-gradle-2.5

    all

  • chainguardeco-java-gradle-2.6

    all

  • chainguardeco-java-gradle-2.7

    all

  • chainguardeco-java-gradle-2.8

    all

  • chainguardeco-java-gradle-2.9

    all

  • chainguardeco-java-gradle-3.0

    all

  • chainguardeco-java-gradle-3.1

    all

  • chainguardeco-java-gradle-3.2

    all

  • chainguardeco-java-gradle-3.2.1

    all

  • chainguardeco-java-gradle-3.3

    all

  • chainguardeco-java-gradle-3.4

    all

  • chainguardeco-java-gradle-3.4.1

    all

  • chainguardeco-java-gradle-3.5

    all

  • chainguardeco-java-gradle-3.5.1

    all

  • chainguardeco-java-gradle-4.0

    all

  • chainguardeco-java-gradle-4.0.1

    all

  • chainguardeco-java-gradle-4.0.2

    all

  • chainguardeco-java-gradle-4.1

    all

  • chainguardeco-java-gradle-4.2

    all

  • chainguardeco-java-gradle-4.2.1

    all

  • chainguardeco-java-gradle-4.3

    all

  • chainguardeco-java-gradle-4.3.1

    all

  • chainguardeco-java-gradle-4.4

    all

  • chainguardeco-java-gradle-4.4.1

    all

  • chainguardhadoop-fips-3.3.6

    all

  • chainguardhadoop-fips-3.4.2

    all

  • chainguardhadoop-fips-3.5

    all

  • debianjackson-databind

    < 2.9.4-1 | < 2.9.4-1 | < 2.9.4-1 | < 2.9.4-1

  • debiandebian_linux

    8.0 | 9.0

  • fasterxmljackson-databind

    ≥ 2.0.0, < 2.6.7.3 | ≥ 2.7.0, < 2.7.9.2 | ≥ 2.8.0, < 2.8.11.1 | ≥ 2.9.0, < 2.9.4

  • com.fasterxml.jackson.corejackson-databind

    ≥ 2.8.0, < 2.8.11.1 | ≥ 2.9.0, < 2.9.4 | < 2.7.9.5

  • netappe-series_santricity_os_controller

    ≥ 11.0.0, ≤ 11.60.3

  • netappe-series_santricity_web_services_proxy

    na

  • netapponcommand_shift

    na

  • redhatjboss_enterprise_application_platform

    7.1

  • redhatopenshift_container_platform

    4.1 | 3.11

  • redhatvirtualization

    4.0

  • redhatvirtualization_host

    4.0

References (20)