CVE-2018-19360: Critical severity fasterxml jackson-databind vulnerability
FasterXML jackson-databind 2.x before 2.9.8 fails to block the axis2-transport-jms class from polymorphic deserialization.
References: https://github.com/FasterXML/jackson-databind/issues/2186 https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8
Upstream Patch: https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b
Other sources
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-19360?
CVE-2018-19360 is a vulnerability in FasterXML jackson-databind 2.x before 2.9.8 that might allow attackers to have an unspecified impact.
How does CVE-2018-19360 work?
CVE-2018-19360 leverages the failure to block the axis2-transport-jms class from polymorphic deserialization.
What is the severity of CVE-2018-19360?
The severity of CVE-2018-19360 is high with a severity score of 5.3.
How can I fix CVE-2018-19360?
To fix CVE-2018-19360, update FasterXML jackson-databind to version 2.9.8 or later.
Where can I find more information about CVE-2018-19360?
You can find more information about CVE-2018-19360 on the following references: [link1], [link2], [link3].