2017-10-16 12:31:07 -04:00
{
2019-07-23 23:01:24 +00:00
"CVE_data_meta" : {
"ASSIGNER" : "secalert@redhat.com" ,
"DATE_PUBLIC" : "2017-04-11T00:00:00" ,
"ID" : "CVE-2017-7525" ,
"STATE" : "PUBLIC"
2019-03-18 00:07:17 +00:00
} ,
2019-07-23 23:01:24 +00:00
"affects" : {
"vendor" : {
"vendor_data" : [
2019-03-18 00:07:17 +00:00
{
2019-07-23 23:01:24 +00:00
"product" : {
"product_data" : [
2019-03-18 00:07:17 +00:00
{
2019-07-23 23:01:24 +00:00
"product_name" : "jackson-databind" ,
"version" : {
"version_data" : [
2019-03-18 00:07:17 +00:00
{
2019-07-23 23:01:24 +00:00
"version_value" : "before 2.6.7.1"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"version_value" : "before 2.7.9.1"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"version_value" : "before 2.8.9"
2019-03-18 00:07:17 +00:00
}
]
}
}
]
} ,
2019-07-23 23:01:24 +00:00
"vendor_name" : "FasterXML"
2019-03-18 00:07:17 +00:00
}
2019-01-16 14:04:51 -05:00
]
2019-03-18 00:07:17 +00:00
}
} ,
2019-07-23 23:01:24 +00:00
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
"value" : "A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper."
2019-03-18 00:07:17 +00:00
}
]
} ,
2019-07-23 23:01:24 +00:00
"problemtype" : {
"problemtype_data" : [
2019-03-18 00:07:17 +00:00
{
2019-07-23 23:01:24 +00:00
"description" : [
2019-03-18 00:07:17 +00:00
{
2019-07-23 23:01:24 +00:00
"lang" : "eng" ,
"value" : "CWE-184"
2019-03-18 00:07:17 +00:00
}
]
}
]
} ,
2019-07-23 23:01:24 +00:00
"references" : {
"reference_data" : [
2019-03-18 00:07:17 +00:00
{
2019-07-23 23:01:24 +00:00
"name" : "1040360" ,
"refsource" : "SECTRACK" ,
"url" : "http://www.securitytracker.com/id/1040360"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:1840" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:1840"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:2547" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:2547"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:1836" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:1836"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:1835" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:1835"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2018:1449" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2018:1449"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "1039744" ,
"refsource" : "SECTRACK" ,
"url" : "http://www.securitytracker.com/id/1039744"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "1039947" ,
"refsource" : "SECTRACK" ,
"url" : "http://www.securitytracker.com/id/1039947"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:2635" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:2635"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:2638" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:2638"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2018:1450" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2018:1450"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:3458" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:3458"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2018:0294" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2018:0294"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:1837" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:1837"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:1834" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:1834"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:2546" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:2546"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:2636" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:2636"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:3455" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:3455"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:2477" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:2477"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:3456" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:3456"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2018:0342" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2018:0342"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:1839" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:1839"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "99623" ,
"refsource" : "BID" ,
"url" : "http://www.securityfocus.com/bid/99623"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:2637" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:2637"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:3454" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:3454"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "DSA-4004" ,
"refsource" : "DEBIAN" ,
"url" : "https://www.debian.org/security/2017/dsa-4004"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:3141" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:3141"
2019-03-18 00:07:17 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"name" : "RHSA-2017:2633" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2017:2633"
2019-03-25 16:00:45 +00:00
} ,
2019-11-12 20:01:53 +00:00
{
"refsource" : "MLIST" ,
"name" : "[lucene-solr-user] 20190104 Re: SOLR v7 Security Issues Caused Denial of Use - Sonatype Application Composition Report" ,
"url" : "https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E"
} ,
2019-03-25 16:00:45 +00:00
{
2019-07-23 23:01:24 +00:00
"refsource" : "MLIST" ,
"name" : "[lucene-dev] 20190325 [jira] [Closed] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ..." ,
"url" : "https://lists.apache.org/thread.html/f60afd3c7e9ebaaf70fad4a4beb75cf8740ac959017a31e7006c7486@%3Cdev.lucene.apache.org%3E"
2019-03-25 16:00:45 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"refsource" : "MLIST" ,
"name" : "[lucene-dev] 20190325 [jira] [Updated] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ..." ,
"url" : "https://lists.apache.org/thread.html/3c87dc8bca99a2b3b4743713b33d1de05b1d6b761fdf316224e9c81f@%3Cdev.lucene.apache.org%3E"
2019-03-25 16:00:45 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"refsource" : "MLIST" ,
"name" : "[lucene-dev] 20190325 [jira] [Assigned] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ..." ,
"url" : "https://lists.apache.org/thread.html/c2ed4c0126b43e324cf740012a0edd371fd36096fd777be7bfe7a2a6@%3Cdev.lucene.apache.org%3E"
2019-03-25 16:00:45 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"refsource" : "MLIST" ,
"name" : "[lucene-dev] 20190325 [jira] [Resolved] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ..." ,
"url" : "https://lists.apache.org/thread.html/c10a2bf0fdc3d25faf17bd191d6ec46b29a353fa9c97bebd7c4e5913@%3Cdev.lucene.apache.org%3E"
2019-04-08 19:00:42 +00:00
} ,
{
2019-07-23 23:01:24 +00:00
"refsource" : "MLIST" ,
"name" : "[lucene-dev] 20190325 [jira] [Updated] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ..." ,
"url" : "https://lists.apache.org/thread.html/b1f33fe5ade396bb903fdcabe9f243f7692c7dfce5418d3743c2d346@%3Cdev.lucene.apache.org%3E"
2019-04-23 04:53:58 -07:00
} ,
2019-04-30 18:00:43 +00:00
{
2019-07-23 23:01:24 +00:00
"refsource" : "REDHAT" ,
"name" : "RHSA-2019:0910" ,
"url" : "https://access.redhat.com/errata/RHSA-2019:0910"
2019-07-16 13:25:12 -07:00
} ,
2019-09-27 03:01:03 +00:00
{
"refsource" : "REDHAT" ,
"name" : "RHSA-2019:2858" ,
"url" : "https://access.redhat.com/errata/RHSA-2019:2858"
2019-10-18 22:01:00 +00:00
} ,
{
"refsource" : "REDHAT" ,
"name" : "RHSA-2019:3149" ,
"url" : "https://access.redhat.com/errata/RHSA-2019:3149"
2019-11-13 07:01:52 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[cassandra-commits] 20191113 [jira] [Created] (CASSANDRA-15416) CVE-2017-7525 ( jackson-databind is vulnerable to Remote Code Execution) on version 3.11.4" ,
"url" : "https://lists.apache.org/thread.html/4641ed8616ccc2c1fbddac2c3dc9900c96387bc226eaf0232d61909b@%3Ccommits.cassandra.apache.org%3E"
2019-11-16 02:02:07 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[druid-commits] 20191115 [GitHub] [incubator-druid] ccaominh opened a new pull request #8878: Address security vulnerabilities" ,
"url" : "https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E"
2019-12-18 16:01:00 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[lucene-solr-user] 20191218 CVE-2017-7525 fix for Solr 7.7.x" ,
"url" : "https://lists.apache.org/thread.html/5008bcbd45ee65ce39e4220b6ac53d28a24d6bc67d5804e9773a7399@%3Csolr-user.lucene.apache.org%3E"
2019-12-18 20:01:36 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[lucene-solr-user] 20191218 Re: CVE-2017-7525 fix for Solr 7.7.x" ,
"url" : "https://lists.apache.org/thread.html/c9d5ff20929e8a3c8794facf4c4b326a9c10618812eec356caa20b87@%3Csolr-user.lucene.apache.org%3E"
2019-12-19 19:01:02 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[lucene-solr-user] 20191219 Re: CVE-2017-7525 fix for Solr 7.7.x" ,
"url" : "https://lists.apache.org/thread.html/f095a791bda6c0595f691eddd0febb2d396987eec5cbd29120d8c629@%3Csolr-user.lucene.apache.org%3E"
2020-02-01 00:01:13 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[debian-lts-announce] 20200131 [SECURITY] [DLA 2091-1] libjackson-json-java security update" ,
"url" : "https://lists.debian.org/debian-lts-announce/2020/01/msg00037.html"
2020-08-24 12:01:23 +00:00
} ,
2020-10-20 22:02:32 +00:00
{
"name" : "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html" ,
"refsource" : "CONFIRM" ,
"url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html"
} ,
{
"name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html" ,
"refsource" : "CONFIRM" ,
"url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html"
} ,
{
"name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html" ,
"refsource" : "CONFIRM" ,
"url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"
} ,
{
"name" : "https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html" ,
"refsource" : "CONFIRM" ,
"url" : "https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html"
} ,
{
"url" : "https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"
} ,
{
"url" : "https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"
} ,
2020-08-24 12:01:23 +00:00
{
"refsource" : "MLIST" ,
"name" : "[debian-lts-announce] 20200824 [SECURITY] [DLA 2342-1] libjackson-json-java security update" ,
"url" : "https://lists.debian.org/debian-lts-announce/2020/08/msg00039.html"
2020-10-20 12:39:21 -07:00
} ,
{
2020-10-20 22:02:32 +00:00
"url" : "https://www.oracle.com/security-alerts/cpuoct2020.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/security-alerts/cpuoct2020.html"
} ,
{
"name" : "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us" ,
"refsource" : "CONFIRM" ,
"url" : "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us"
} ,
{
"name" : "https://github.com/FasterXML/jackson-databind/issues/1723" ,
"refsource" : "CONFIRM" ,
"url" : "https://github.com/FasterXML/jackson-databind/issues/1723"
} ,
{
"name" : "https://github.com/FasterXML/jackson-databind/issues/1599" ,
"refsource" : "CONFIRM" ,
"url" : "https://github.com/FasterXML/jackson-databind/issues/1599"
} ,
{
"name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1462702" ,
"refsource" : "CONFIRM" ,
"url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1462702"
} ,
{
"name" : "https://security.netapp.com/advisory/ntap-20171214-0002/" ,
"refsource" : "CONFIRM" ,
"url" : "https://security.netapp.com/advisory/ntap-20171214-0002/"
} ,
{
"name" : "https://cwiki.apache.org/confluence/display/WW/S2-055" ,
"refsource" : "CONFIRM" ,
"url" : "https://cwiki.apache.org/confluence/display/WW/S2-055"
2021-02-23 20:00:39 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[spark-issues] 20210223 [jira] [Created] (SPARK-34511) Current Security vulnerabilities in spark libraries" ,
"url" : "https://lists.apache.org/thread.html/r68acf97f4526ba59a33cc6e592261ea4f85d890f99e79c82d57dd589@%3Cissues.spark.apache.org%3E"
2021-09-27 17:01:02 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[cassandra-commits] 20210927 [jira] [Commented] (CASSANDRA-15416) CVE-2017-7525 ( jackson-databind is vulnerable to Remote Code Execution) on version 3.11.4" ,
"url" : "https://lists.apache.org/thread.html/rf7f87810c38dc9abf9f93989f76008f504cbf7c1a355214640b2d04c@%3Ccommits.cassandra.apache.org%3E"
2021-09-27 19:01:14 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[cassandra-commits] 20210927 [jira] [Updated] (CASSANDRA-15416) CVE-2017-7525 ( jackson-databind is vulnerable to Remote Code Execution) on version 3.11.4" ,
"url" : "https://lists.apache.org/thread.html/r42ac3e39e6265db12d9fc6ae1cd4b5fea7aed9830dc6f6d58228fed7@%3Ccommits.cassandra.apache.org%3E"
2019-03-18 00:07:17 +00:00
}
]
}
}