Back

CRITICAL

jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-15095)

Published Jan 10, 2018

Description

FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (39)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 10, 2018
Updated Aug 27, 2025
Reserved Dec 10, 2017
CISA Vulnrichment
Updated Aug 27, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 12, 2017
GHSA-RFX6-VP9G-RH7V