VDB
CVE-2018-21234
CVE-2018-21234
PUBLISHED
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
EPSS 25.25% · 96.3th percentile
Risk Scores
EPSS Score
25.25%
96.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:22.04:LTS | jodd | 0, 3.8.6-1.1 |
| Ubuntu:20.04:LTS | jodd | 0, 3.8.6-1 |
Exploit Intelligence
- https://github.com/oblac/jodd/issues/628 (circl)
- https://github.com/oblac/jodd/compare/v5.0.3...v5.0.4 (circl)
- https://github.com/oblac/jodd/commit/9bffc3913aeb8472c11bb543243004b4b4376f16 (circl)
- [hive-issues] 20210423 [jira] [Assigned] (HIVE-25054) Upgrade jodd-core due to CVE-2018-21234 (circl)
- [hive-dev] 20210423 [jira] [Created] (HIVE-25054) Upgrade jodd-core due to CVE-2018-21234 (circl)
- [hive-issues] 20210423 [jira] [Work started] (HIVE-25054) Upgrade jodd-core due to CVE-2018-21234 (circl)
- [hive-issues] 20210423 [jira] [Updated] (HIVE-25054) Upgrade jodd-core due to CVE-2018-21234 (circl)
- [hive-gitbox] 20210423 [GitHub] [hive] achennagiri opened a new pull request #2217: HIVE:25054 Upgrade `jodd-core` dependency to get rid of CVE-2018-21234 (circl)
- [hive-issues] 20210518 [jira] [Commented] (HIVE-25054) Upgrade jodd-core due to CVE-2018-21234 (circl)
- [hive-gitbox] 20210520 [GitHub] [hive] achennagiri commented on a change in pull request #2217: HIVE:25054 Upgrade `jodd-core` dependency to get rid of CVE-2018-21234 (circl)
…and 4 more exploits
Timeline
- May 21, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Apr 27, 2021 EPSS Score
- May 25, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 12, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 26, 2022 CVE Updated
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-21234 third-party-advisory
- https://github.com/oblac/jodd/commit/9bffc3913aeb8472c11bb543243004b4b4376f16 third-party-advisory
- https://github.com/oblac/jodd/issues/628 third-party-advisory
- https://github.com/oblac/jodd/compare/v5.0.3...v5.0.4 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-21234 third-party-advisory