CVE-2018-11307: Critical severity fasterxml jackson-databind vulnerability
A vulnerability was found in FasterXML jackson-databind before versions 2.7.9.4, 2.8.11.2, 2.9.6. A new potential gadget type from MyBatis (https://github.com/mybatis/mybatis-3) has been reported. It may allow content exfiltration (remote access by sending contents over ftp) when untrusted content is deserialized with default typing enabled.
Upstream Bug: https://github.com/FasterXML/jackson-databind/issues/2032
References: https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.8
Other sources
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-11307?
CVE-2018-11307 is a vulnerability in FasterXML jackson-databind that allows exfiltration of content.
What is the severity of CVE-2018-11307?
The severity of CVE-2018-11307 is critical with a CVSS score of 9.8.
How does CVE-2018-11307 affect FasterXML jackson-databind?
CVE-2018-11307 affects FasterXML jackson-databind versions 2.0.0 through 2.9.5.
How do I fix CVE-2018-11307 in FasterXML jackson-databind?
To fix CVE-2018-11307 in FasterXML jackson-databind, update to version 2.7.9.4, 2.8.11.2, or 2.9.6.
Where can I find more information about CVE-2018-11307?
You can find more information about CVE-2018-11307 at the following references: [link1](https://github.com/mybatis/mybatis-3), [link2](https://github.com/FasterXML/jackson-databind/issues/2032), [link3](https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.8).