漏洞信息详情
FasterXML Jackson-databind 代码问题漏洞
漏洞简介
FasterXML jackson-databind是一个基于JAVA可以将XML和JSON等数据格式与JAVA对象进行转换的库。Jackson可以轻松的将Java对象转换成json对象和xml文档,同样也可以将json、xml转换成Java对象。
FasterXML Jackson-databind 2.8.10及之前版本和2.9.x版本至2.9.3版本中存在代码问题漏洞。远程攻击者可通过向ObjectMapper的readValue方法发送恶意制作的JSON输入并绕过黑名单利用该漏洞执行代码。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/FasterXML/jackson-databind/issues/1855
参考网址
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:0342
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:1450
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:1797
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:2858
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:1451
来源:CONFIRM
链接:https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:0480
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:3149
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:0481
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuoct2020.html
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:1449
来源:CONFIRM
链接:https://github.com/FasterXML/jackson-databind/issues/1855
来源:BUGTRAQ
链接:http://www.securityfocus.com/archive/1/541652/100/0/threaded
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:0116
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:0479
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:1447
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:1448
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:0478
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2018:2930
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:1782
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:3892
来源:DEBIAN
链接:https://www.debian.org/security/2018/dsa-4114
来源:MISC
链接:https://github.com/irsl/jackson-rce-via-spel/
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20180201-0003/
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:3892
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10885606
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=swg22017294
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10885608
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:1782
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10872142
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:2858
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/75922
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-guardium-data-encryption-gde-3/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/76430
来源:www.nsfocus.net
链接:http://www.nsfocus.net/vulndb/48707
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4254/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2630/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.4332/
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10870976
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-infosphere-information-server-is-affected-by-multiple-vulnerabilities-in-jackson-databind/
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10885602
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/155352/Red-Hat-Security-Advisory-2019-3892-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.3643/
来源:www-01.ibm.com
链接:https://www-01.ibm.com/support/docview.wss?uid=ibm10872142
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.1988/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-has-announced-a-release-for-ibm-security-identity-governance-and-intelligence-in-response-to-security-vulnerabilities-3/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-third-party-vulnerable-library-jackson-databind-affects-ibm-engineering-lifecycle-optimization-publishing/
受影响实体
- Fasterxml Jackson-Databind:2.9.2<!--2000-1-1-->
- Fasterxml Jackson-Databind:2.9.3<!--2000-1-1-->
- Fasterxml Jackson-Databind:2.9.1<!--2000-1-1-->
- Fasterxml Jackson-Databind:2.8.10<!--2000-1-1-->
- Fasterxml Jackson:1.0.0<!--2000-1-1-->
补丁
- FasterXML Jackson-databind 安全漏洞的修复措施<!--2017-12-11-->
还没有评论,来说两句吧...