Back

CRITICAL

jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis

Published Jul 9, 2019

Description

An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.

Affected products

Remediation

Red Hat statement

Red Hat Satellite 6 is not affected by this issue, since Candlepin's java runtime environment does not load MyBatis classes. Red Hat Virtualization 4 is not affected by this issue, since it does not include MyBatis classes. Red Hat Fuse 6 and 7 are not directly affected by this issue, as although they do ship the vulnerable jackson-databind component, they do not enable polymorphic deserialization or default typing which are required for exploitability. Their impacts have correspondingly been reduced to Moderate. Future updates may address this flaw.

Metrics

References (34)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 9, 2019
Updated Aug 5, 2024
Reserved May 18, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 10, 2018
GHSA-QR7J-H6GG-JMGC