CVE-2018-14720

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
02/01/2019
Last modified:
07/11/2023

Description

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* 2.6.0 (including) 2.6.7.2 (excluding)
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* 2.7.0 (including) 2.7.9.5 (excluding)
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* 2.8.0 (including) 2.8.11.3 (excluding)
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* 2.9.0 (including) 2.9.7 (excluding)
cpe:2.3:a:fasterxml:jackson-databind:2.7.0:rc1:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:2.7.0:rc2:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:2.7.0:rc3:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:2.8.0:rc1:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:2.8.0:rc2:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:2.9.0:pr1:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:2.9.0:pr2:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:2.9.0:pr3:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:2.9.0:pr4:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools