CVE-2018-19361: Critical severity fasterxml jackson-databind vulnerability
FasterXML jackson-databind 2.x before 2.9.8 fails to block the openjpa class from polymorphic deserialization.
References: https://github.com/FasterXML/jackson-databind/issues/2186 https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8
Upstream Patch: https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b
Other sources
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-19361?
CVE-2018-19361 is an unspecified error with failure to block the openjpa class from polymorphic deserialization in FasterXML jackson-databind before version 2.9.8.
How does CVE-2018-19361 impact the system?
CVE-2018-19361 may allow attackers to have an unspecified impact by leveraging the failure to block the openjpa class from polymorphic deserialization.
What is the severity of CVE-2018-19361?
CVE-2018-19361 has a severity score of 5.3 (High).
Which software versions are affected by CVE-2018-19361?
CVE-2018-19361 affects FasterXML jackson-databind versions 2.9.7 and earlier.
How can CVE-2018-19361 be fixed?
To fix CVE-2018-19361, upgrade to FasterXML jackson-databind version 2.9.8 or later.