漏洞信息详情
FasterXML jackson-databind 代码问题漏洞
漏洞简介
FasterXML jackson-databind是一个基于JAVA可以将XML和JSON等数据格式与JAVA对象进行转换的库。Jackson可以轻松的将Java对象转换成json对象和xml文档,同样也可以将json、xml转换成Java对象。
FasterXML Jackson-databind 2.8.11及之前版本和2.9.x版本至2.9.3版本中存在代码问题漏洞。该漏洞源于网络系统或产品的代码开发过程中存在设计或实现不当的问题。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/FasterXML/jackson-databind/commit/038b471e2efde2e8f96b4e0be958d3e5a1ff1d05
参考网址
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:0479
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20180423-0002/
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:1525
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:0478
来源:MISC
链接:https://github.com/FasterXML/jackson-databind/issues/1899
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:2858
来源:CONFIRM
链接:https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us
来源:DEBIAN
链接:https://www.debian.org/security/2018/dsa-4114
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:0480
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:3149
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:0481
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuoct2020.html
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10872142
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:2858
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/75922
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-infosphere-information-server-is-affected-by-multiple-vulnerabilities-in-jackson-databind/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-guardium-data-encryption-gde-3/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-fasterxml-jackson-databind-affect-apache-solr-shipped-with-ibm-operations-analytics-log-analysis/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/76430
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.3643/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/154913/Red-Hat-Security-Advisory-2019-3149-01.html
来源:www-01.ibm.com
链接:https://www-01.ibm.com/support/docview.wss?uid=ibm10872142
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4254/
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10870976
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-third-party-vulnerable-library-jackson-databind-affects-ibm-engineering-lifecycle-optimization-publishing/
受影响实体
- Fasterxml Jackson-Databind:2.9.3<!--2000-1-1-->
- Fasterxml Jackson-Databind:2.9.2<!--2000-1-1-->
- Fasterxml Jackson-Databind:2.9.1<!--2000-1-1-->
- Fasterxml Jackson-Databind:2.9.0<!--2000-1-1-->
- Fasterxml Jackson-Databind:2.8.11<!--2000-1-1-->
补丁
- FasterXML jackson-databind 安全漏洞的修复措施<!--2018-1-23-->
还没有评论,来说两句吧...