cbcvebase.
CVE-2017-7525
published 2018-02-06

CVE-2017-7525: A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform…

PriorityP276critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
37.92%
98.4th percentile
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

Affected

87 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianjackson-databind< jackson-databind 2.9.4-1 (bookworm)jackson-databind 2.9.4-1 (bookworm)
debianjackson-databind< jackson-databind 2.9.5-1 (bookworm)jackson-databind 2.9.5-1 (bookworm)
debianjackson-databind< jackson-databind 2.9.1-1 (bookworm)jackson-databind 2.9.1-1 (bookworm)
debianlibjackson-json-java< jackson-databind 2.9.1-1 (bookworm)jackson-databind 2.9.1-1 (bookworm)
fasterxmljackson-databind< 2.6.7.32.6.7.3
fasterxmljackson-databind< 2.7.9.32.7.9.3
fasterxmljackson-databind< 2.6.7.12.6.7.1
fasterxmljackson-databind
fasterxmljackson-databind>= 0 < 2.9.4-12.9.4-1
fasterxmljackson-databind>= 0 < 2.9.1-12.9.1-1
fasterxmljackson-databind>= 0 < 2.9.5-12.9.5-1
fasterxmljackson-databind>= 0 < 2.9.4-12.9.4-1
fasterxmljackson-databind>= 0 < 2.9.1-12.9.1-1
fasterxmljackson-databind>= 0 < 2.9.5-12.9.5-1
fasterxmljackson-databind>= 0 < 2.9.4-12.9.4-1
fasterxmljackson-databind>= 0 < 2.9.1-12.9.1-1
fasterxmljackson-databind>= 0 < 2.9.5-12.9.5-1
fasterxmljackson-databind>= 0 < 2.9.4-12.9.4-1
fasterxmljackson-databind>= 0 < 2.9.1-12.9.1-1
fasterxmljackson-databind>= 0 < 2.9.5-12.9.5-1
fasterxmljackson-databind>= 2.0.0 < 2.6.7.22.6.7.2
fasterxmljackson-databind>= 2.0.0 < 2.6.7.32.6.7.3
fasterxmljackson-databind>= 2.7.0 < 2.7.9.22.7.9.2

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2017-7525 is exploitable by sending maliciously crafted input to the readValue method of the ObjectMapper in jackson-databind; trigger requires enableDefaultTyping() to be active for polymorphic deserialization
  • The vulnerability requires global polymorphic deserialization to be enabled via objectMapper.enableDefaultTyping(); absence of this call significantly reduces exploitability
  • CVE-2017-7525 has been repeatedly bypassed via new gadget chains not covered by the blacklist; monitor for follow-on CVEs (CVE-2017-15095, CVE-2017-17485, CVE-2018-5968, CVE-2018-7489) as indicators of the same attack surface
  • c3p0 libraries on the classpath can be used as a gadget to bypass the jackson-databind blacklist and achieve RCE via CVE-2017-7525 follow-on; audit classpath for c3p0 presence
  • ·Exploitation of CVE-2017-7525 requires enableDefaultTyping() to be called on the ObjectMapper; applications that do NOT call this globally are not directly vulnerable even if running an affected version
  • ·JBoss EAP 7.x exposure is limited to marshalling/unmarshalling of JSON objects passed to JAX-RS webservices; review JAX-RS endpoint configurations specifically

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.