High severity8.1NVD Advisory· Published Jan 22, 2018· Updated Jun 17, 2026
CVE-2018-5968
CVE-2018-5968
Description
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.fasterxml.jackson.core:jackson-databindMaven | >= 2.8.0, < 2.8.11.1 | 2.8.11.1 |
com.fasterxml.jackson.core:jackson-databindMaven | >= 2.9.0, < 2.9.4 | 2.9.4 |
com.fasterxml.jackson.core:jackson-databindMaven | < 2.7.9.5 | 2.7.9.5 |
Affected products
12- cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*Range: >=2.0.0,<2.6.7.3
cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*Range: >=11.0.0,<=11.60.3
- cpe:2.3:a:netapp:e-series_santricity_web_services_proxy:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:oncommand_shift:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
19- access.redhat.com/errata/RHSA-2018:0478nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:0479nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:0480nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:0481nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:1525nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2858nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:3149nvdThird Party AdvisoryWEB
- github.com/FasterXML/jackson-databind/issues/1899nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-w3f4-3q6j-rh82ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-5968ghsaADVISORY
- security.netapp.com/advisory/ntap-20180423-0002/nvdThird Party Advisory
- support.hpe.com/hpsc/doc/public/displaynvdThird Party AdvisoryWEB
- www.debian.org/security/2018/dsa-4114nvdThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuoct2020.htmlnvdThird Party AdvisoryWEB
- github.com/FasterXML/jackson-databind/commit/038b471e2efde2e8f96b4e0be958d3e5a1ff1d0ghsaWEB
- github.com/FasterXML/jackson-databind/commit/03ea0bec6293d4330b5ad19d1d62aca0e3cb6381ghsaWEB
- github.com/FasterXML/jackson-databind/commit/454be8bb8c913be18298327a84ca45a280b61605ghsaWEB
- github.com/GulajavaMinistudio/jackson-databind/pull/92/commits/038b471e2efde2e8f96b4e0be958d3e5a1ff1d05ghsaWEB
- security.netapp.com/advisory/ntap-20180423-0002ghsaWEB
News mentions
0No linked articles in our index yet.