Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upCVE-2017-7525 -- com.fasterxml.jackson.core:jackson-databind #279
Comments
ruebot
added
the
security
label
Oct 16, 2018
ruebot
self-assigned this
Oct 16, 2018
added a commit
to ruebot/aut
that referenced
this issue
Oct 16, 2018
ruebot
referenced this issue
Oct 16, 2018
Merged
Update jackson-databind version; resolves #279. #280
ianmilligan1
closed this
in
72cb5e2
Oct 16, 2018
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
ruebot commentedOct 16, 2018
GitHub alert:
CVE-2017-7525 More information
high severity
Vulnerable versions: >= 2.8.0, < 2.8.9
Patched version: 2.8.9
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
https://nvd.nist.gov/vuln/detail/CVE-2017-7525