RHSA-2018:0116: Important: rh-eclipse46-jackson-databind security update
The jackson-databind package provides general data-binding functionality for Jackson, which works on top of Jackson core streaming API.Security Fix(es): A deserialization flaw was discovered in the jackson-databind which could allow an unauthenticated user to perform code execution by sending maliciously crafted input to the readValue method of ObjectMapper. This issue extends upon the previous flaws CVE-2017-7525 and CVE-2017-15095 by blacklisting more classes that could be used maliciously. (CVE-2017-17485) Red Hat would like to thank 0c0c0f from 360观星实验室 for reporting this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:0116?
The severity of RHSA-2018:0116 is classified as important.
How do I fix RHSA-2018:0116?
To fix RHSA-2018:0116, update the jackson-databind package to version 2.6.3-2.6.el7 or higher.
What type of vulnerability is addressed in RHSA-2018:0116?
RHSA-2018:0116 addresses a deserialization flaw in the jackson-databind package.
Who is affected by RHSA-2018:0116?
RHSA-2018:0116 affects users of the jackson-databind package up to version 2.6.3-2.6.el7.
Is authentication required to exploit the vulnerability in RHSA-2018:0116?
No, the vulnerability in RHSA-2018:0116 can be exploited by an unauthenticated user.