CVE-2018-14719: Critical severity fasterxml jackson-databind vulnerability
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
Other sources
FasterXML jackson-databind 2.x before 2.9.7, 2.8.11.3, and 2.7.9.5 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14719?
CVE-2018-14719 has a critical severity level as it allows remote attackers to execute arbitrary code.
How do I fix CVE-2018-14719?
To fix CVE-2018-14719, upgrade to jackson-databind version 2.9.7 or later, or apply the recommended versions as specified in the advisory.
What versions are affected by CVE-2018-14719?
CVE-2018-14719 affects FasterXML jackson-databind versions before 2.9.7, including 2.6.x, 2.7.x, and 2.8.x.
Can CVE-2018-14719 impact my application?
Yes, if your application uses vulnerable versions of jackson-databind, it may be susceptible to remote code execution due to this vulnerability.
Is there a workaround for CVE-2018-14719?
While upgrading is the best approach, a temporary workaround is to avoid polymorphic deserialization if feasible in your application.