CVE-2018-19362
FasterXML jackson-databind 2.x before 2.9.8 fails to block the jboss-common-core class from polymorphic deserialization. References: https://github.com/FasterXML/jackson-databind/issues/2186 https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8 Upstream Patch: https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-19362?
CVE-2018-19362 is an unspecified error with failure to block the jboss-common-core class from polymorphic deserialization in FasterXML jackson-databind before version 2.9.8.
How does CVE-2018-19362 impact the affected software?
CVE-2018-19362 might allow attackers to have unspecified impact on the affected software by leveraging the failure to block the jboss-common-core class from polymorphic deserialization in FasterXML jackson-databind.
Is there a specific version of jackson-databind affected by CVE-2018-19362?
Yes, the affected versions of jackson-databind are 2.7.9.5, 2.8.11.3, and versions prior to 2.9.8.
What is the severity of CVE-2018-19362?
CVE-2018-19362 has a severity level of 5.3 (high).
How do I fix CVE-2018-19362?
To fix CVE-2018-19362, update your installation of FasterXML jackson-databind to version 2.9.8 or higher.