UBUNTU-CVE-2018-12023
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-12023
UBUNTU-CVE-2018-12023
Summary:
Details: An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.
References: https://ubuntu.com/security/CVE-2018-12023, https://github.com/FasterXML/jackson-databind/issues/2058, https://github.com/FasterXML/jackson-databind/commit/7487cf7eb14be2f65a1eb108e8629c07ef45e0a1, https://ubuntu.com/security/notices/USN-4813-1, https://www.cve.org/CVERecord?id=CVE-2018-12023
Affected packages
Package
Name: jackson-databind
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
