CVE-2018-7489

Aliases:GHSA-cggj-fvv3-cqwvRHEA-2018:2082DEBIAN-CVE-2018-7489CGA-2663-46vw-8cq6CGA-2gwr-j45w-qprfCGA-2p6q-h762-wc3xCGA-38q6-8qhv-hqp4CGA-3v3v-m4ch-89wxCGA-42h6-3c94-63f4CGA-4cm3-c757-w5m3CGA-4jqp-ccxw-mx69CGA-4xpc-m968-5whcCGA-53x2-phfx-m8mcCGA-623f-j3mh-vj3hCGA-6xhj-p2pv-c45vCGA-794p-cf52-7775CGA-7hw9-qxxh-x343CGA-834c-w6vq-m57gCGA-88c5-qgrr-mwp2CGA-8qqw-7726-c2fjCGA-9r9h-x4w3-hmf5CGA-c2jw-hh7v-g55hCGA-chrr-c82r-rr24CGA-h73m-rwjf-v3gfCGA-hmw3-hr3q-5q76CGA-hw97-f9hw-26r8CGA-jcc7-g9vm-j42mCGA-jcjp-4ggf-r72hCGA-jqvg-hfj7-pmgvCGA-q26q-8m3q-r2cfCGA-qg7q-fxhp-4w89CGA-qmx2-8jxh-xpm5CGA-qwxh-3c59-p65pCGA-r5v2-wjhx-4p3qCGA-rvr9-44mh-jpq9CGA-v6hm-gx35-2r7rCGA-wqcj-qg4v-wvpwCGA-24ch-vwrc-w2mvCGA-2f7g-8h94-422fCGA-4jg3-c396-6whvCGA-5926-47q6-m5g6CGA-fc2f-2hx3-79h7CGA-g3q2-8mfj-fwj7CGA-gfqf-f99j-4p27CGA-j85v-fj22-8hfpCGA-j8jh-p82w-57v7CGA-jf4v-35vw-8c6pCGA-jf74-prfr-h48qCGA-m53g-v6xp-gj64CGA-phrx-5f6m-rrjmCGA-rc29-4hw7-f425CGA-v86v-p72x-gcr7CGA-wg2g-484g-q239CGA-whgw-pmqr-rjrjCGA-x26g-6m7g-9j37CGA-3xf7-hwhj-rqpqCGA-5j98-g4q7-982cCGA-7hr4-mf2f-3qmrCGA-8gcr-wj5p-hcccCGA-8mcj-g33x-m574CGA-8qhv-2q27-737rCGA-9mqj-vg8v-chg7CGA-cchq-742h-j425CGA-f6x3-45p8-6p43CGA-fp9h-2gpx-rrrrCGA-gr68-w84w-8v5jCGA-hqh6-hjqp-5jgmCGA-hvwq-2hx3-xf8gCGA-jpg4-8rgc-rg85CGA-mhgp-cjfh-88rgCGA-p83h-hjvx-7gfgCGA-qq5v-r23w-3mmxCGA-rxg2-6vp8-qx94CGA-v9m8-w7r9-7gp9CGA-vg3x-72fj-g3hqCGA-vv94-73x4-7pvgCGA-w26v-x2pv-mr7hCGA-wmg7-2prv-8r67CGA-x5r7-278q-x4w8CGA-xc94-8fcj-5rh5CGA-28x7-v9m6-45xvCGA-3qjh-584h-m94qCGA-3xff-34gf-jq3rCGA-4fv7-vwm9-cgmqCGA-56r5-xjmf-fv23CGA-5c4h-88cm-6gfqCGA-6w69-28j3-q474CGA-9cpc-95rq-g556CGA-9xhp-m27r-mmgrCGA-cxh8-hcp9-4q4fCGA-fwpc-33qf-c8pxCGA-gcmq-gmx2-q93gCGA-gg4v-mrqf-35vmCGA-gq5x-x6pm-6f32CGA-gq7r-8rhg-6qm6CGA-hjp9-4px7-ppvfCGA-m449-m898-xx6mCGA-mcfm-xh5f-jv2cCGA-qv92-qj6g-8p7vCGA-r7f2-6hrm-mf9xCGA-wv56-8hmm-vq3w
Advisory lineage Upstream: 0 Downstream: 11
Modified
Published: 26 Feb 2018, 15:00
Last modified:05 Aug 2024, 06:31

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.0 (nvd)
EPSS Score
19.78% MEDIUM
20% probability -16.43%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Feb 2018, 15:00
Published
Vulnerability first disclosed
05 Aug 2024, 06:31
Last Modified
Vulnerability information updated

Description

FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.

CVSS Metrics

  • v3.0CRITICALScore: 9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v3.0HIGHScore: 8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 19.78% Percentile: 97%

Techniques & Countermeasures

  • CWE-184Incomplete List of Disallowed Inputs

    The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • chainguardeco-java-gradle-2.10

    all

  • chainguardeco-java-gradle-2.11

    all

  • chainguardeco-java-gradle-2.12

    all

  • chainguardeco-java-gradle-2.13

    all

  • chainguardeco-java-gradle-2.14

    all

  • chainguardeco-java-gradle-2.14.1

    all

  • chainguardeco-java-gradle-2.4

    all

  • chainguardeco-java-gradle-2.5

    all

  • chainguardeco-java-gradle-2.6

    all

  • chainguardeco-java-gradle-2.7

    all

  • chainguardeco-java-gradle-2.8

    all

  • chainguardeco-java-gradle-2.9

    all

  • chainguardeco-java-gradle-3.0

    all

  • chainguardeco-java-gradle-3.1

    all

  • chainguardeco-java-gradle-3.2

    all

  • chainguardeco-java-gradle-3.2.1

    all

  • chainguardeco-java-gradle-3.3

    all

  • chainguardeco-java-gradle-3.4

    all

  • chainguardeco-java-gradle-3.4.1

    all

  • chainguardeco-java-gradle-3.5

    all

  • chainguardeco-java-gradle-3.5.1

    all

  • chainguardeco-java-gradle-4.0

    all

  • chainguardeco-java-gradle-4.0.1

    all

  • chainguardeco-java-gradle-4.0.2

    all

  • chainguardeco-java-gradle-4.1

    all

  • chainguardeco-java-gradle-4.10

    all

  • chainguardeco-java-gradle-4.10.1

    all

  • chainguardeco-java-gradle-4.10.2

    all

  • chainguardeco-java-gradle-4.10.3

    all

  • chainguardeco-java-gradle-4.2

    all

  • chainguardeco-java-gradle-4.2.1

    all

  • chainguardeco-java-gradle-4.3

    all

  • chainguardeco-java-gradle-4.3.1

    all

  • chainguardeco-java-gradle-4.4

    all

  • chainguardeco-java-gradle-4.4.1

    all

  • chainguardeco-java-gradle-4.5

    all

  • chainguardeco-java-gradle-4.5.1

    all

  • chainguardeco-java-gradle-4.6

    all

  • chainguardeco-java-gradle-4.7

    all

  • chainguardeco-java-gradle-4.8

    all

  • chainguardeco-java-gradle-4.8.1

    all

  • chainguardeco-java-gradle-4.9

    all

  • chainguardhadoop-fips-3.3.6

    all

  • chainguardhadoop-fips-3.4.2

    all

  • chainguardhadoop-fips-3.5

    all

  • debianjackson-databind

    < 2.9.5-1 | < 2.9.5-1 | < 2.9.5-1 | < 2.9.5-1

  • debiandebian_linux

    8.0 | 9.0

  • fasterxmljackson-databind

    < 2.7.9.3 | ≥ 2.8.0, < 2.8.11.1 | ≥ 2.9.0, < 2.9.5

  • com.fasterxml.jackson.corejackson-databind

    ≥ 2.8.0, < 2.8.11.1 | ≥ 2.9.0, < 2.9.5 | ≥ 2.7.0, < 2.7.9.3 | < 2.6.7.5

  • oraclecommunications_billing_and_revenue_management

    7.5 | 12.0

Showing first 50 affected entries in server-rendered view.

References (46)