VDB
BDU%3A2018-00945
BDU%3A2018-00945
PUBLISHED
CVSS 7.5 HIGH
Уязвимость компонента ObjectMapper библиотеки FasterXML jackson-databind, позволяющая нарушителю обойти ограничения «черного списка» и выполнить произвольный код
Risk Scores
CVSS 2.0
7.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, FasterXML, LLC, ООО «РусБИТех-Астра», Oracle Corp. | Debian GNU/Linux, Jackson-databind, Astra Linux Common Edition (запись в едином реестре российских программ №4433), Communications Instant Messaging Server, Communications Billing and Revenue Management, Retail Workforce Management Software, Global Lifecycle Management |
Timeline
- Aug 3, 2018 CVE Published
- Feb 28, 2023 CVE Updated
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Security Advisory
References
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html url
- https://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html url
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html url
- https://www.debian.org/security/2018/dsa-4190 url
- http://fasterxml.com/ url
- https://tools.cisco.com/security/center/viewAlert.x?alertId=57265 url
- https://access.redhat.com/security/cve/cve-2018-7489 url
- https://www.securityfocus.com/bid/103203 url
- https://github.com/FasterXML/jackson-databind/issues/1931 url