Bug 1528565 (CVE-2017-17485)
Summary: | CVE-2017-17485 jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-15095) | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jason Shepherd <jshepherd> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | abhgupta, ahardin, aileenc, alazarot, anstephe, bcourt, bkearney, bleanhar, bmaxwell, bmcclain, ccoleman, cdewolf, chazlett, csutherl, darran.lofthouse, dblechte, dedgar, dimitris, dosoudil, drieden, drusso, eedri, etirelli, fgavrilo, ggaughan, ibek, janstey, java-sig-commits, jawilson, jcoleman, jgoulding, jmadigan, jmatthew, jochrist, jolee, jondruse, jshepherd, jstastny, krathod, kverlaen, lef, lgao, lgriffin, loleary, lpetrovi, lsurette, mchappel, mgoldboi, michal.skrivanek, mmccune, mrike, myarboro, ngough, nwallace, ohadlevy, paradhya, pavelp, pbraun, pgier, pjurak, ppalaga, psakar, pslavice, psotirop, puntogil, pwright, rchan, Rhev-m-bugs, rnetuka, rrajasek, rstancel, rsvoboda, rsynek, rzhang, sdaley, sherold, spinder, srevivo, theute, tiwillia, trepel, tsanders, twalsh, vhalbert, vkadlcik, vtunka, ykaul |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
A deserialization flaw was discovered in the jackson-databind which could allow an unauthenticated user to perform code execution by sending maliciously crafted input to the readValue method of ObjectMapper. This issue extends upon the previous flaws CVE-2017-7525 and CVE-2017-15095 by blacklisting more classes that could be used maliciously.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2019-06-08 03:34:52 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1530463, 1530464, 1530471, 1530472, 1530473, 1530474, 1534307, 1537880, 1585895, 1730588, 1731780, 1731787, 1731789, 1731790, 1731792, 1732286, 1732291, 1732539 | ||
Bug Blocks: | 1523223 |
Description
Jason Shepherd
2017-12-22 07:14:56 UTC
Created jackson-databind tracking bugs for this issue: Affects: fedora-all [bug 1530463] Acknowledgements: Name: 0c0c0f from 360观星实验室 This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS Via RHSA-2018:0116 https://access.redhat.com/errata/RHSA-2018:0116 This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS Via RHSA-2018:0342 https://access.redhat.com/errata/RHSA-2018:0342 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2018:0478 https://access.redhat.com/errata/RHSA-2018:0478 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 Via RHSA-2018:0480 https://access.redhat.com/errata/RHSA-2018:0480 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 Via RHSA-2018:0479 https://access.redhat.com/errata/RHSA-2018:0479 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 Via RHSA-2018:0481 https://access.redhat.com/errata/RHSA-2018:0481 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2018:1447 https://access.redhat.com/errata/RHSA-2018:1447 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 Via RHSA-2018:1448 https://access.redhat.com/errata/RHSA-2018:1448 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Via RHSA-2018:1449 https://access.redhat.com/errata/RHSA-2018:1449 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5 Via RHSA-2018:1450 https://access.redhat.com/errata/RHSA-2018:1450 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Via RHSA-2018:1451 https://access.redhat.com/errata/RHSA-2018:1451 EAP 6.4 uses whitelist approach which enables to enlist classes with the use of the system property. Please see the following article for details: https://access.redhat.com/solutions/3442891 External References: https://access.redhat.com/solutions/3442891 This issue has been addressed in the following products: Red Hat JBoss Operations Network Via RHSA-2018:2930 https://access.redhat.com/errata/RHSA-2018:2930 This issue has been addressed in the following products: Red Hat JBoss BRMS 6.4.12 Via RHSA-2019:1782 https://access.redhat.com/errata/RHSA-2019:1782 This issue has been addressed in the following products: Red Hat Process Automation Via RHSA-2019:1797 https://access.redhat.com/errata/RHSA-2019:1797 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.1 Via RHSA-2019:2858 https://access.redhat.com/errata/RHSA-2019:2858 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.11 Via RHSA-2019:3149 https://access.redhat.com/errata/RHSA-2019:3149 This issue has been addressed in the following products: Red Hat Fuse 7.5.0 Via RHSA-2019:3892 https://access.redhat.com/errata/RHSA-2019:3892 |