cbcvebase.
CVE-2018-14718
published 2019-01-02

CVE-2018-14718: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from…

PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
12.68%
95.8th percentile
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.

Affected

60 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianjackson-databind< jackson-databind 2.9.8-1 (bookworm)jackson-databind 2.9.8-1 (bookworm)
fasterxmljackson-databind>= 0 < 2.9.8-12.9.8-1
fasterxmljackson-databind>= 0 < 2.9.8-12.9.8-1
fasterxmljackson-databind>= 0 < 2.9.8-12.9.8-1
fasterxmljackson-databind>= 0 < 2.9.8-12.9.8-1
fasterxmljackson-databind>= 0 < 2.4.2-3ubuntu0.1~esm22.4.2-3ubuntu0.1~esm2
fasterxmljackson-databind>= 2.0.0 < 2.6.7.32.6.7.3
fasterxmljackson-databind>= 2.7.0 < 2.7.9.52.7.9.5
fasterxmljackson-databind>= 2.8.0 < 2.8.11.32.8.11.3
fasterxmljackson-databind>= 2.9.0 < 2.9.72.9.7
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebusiness_process_management_suite
oraclebusiness_process_management_suite
oraclecommunications_billing_and_revenue_management
oraclecommunications_billing_and_revenue_management
oraclecommunications_instant_messaging_server
oracleenterprise_manager_for_virtualization
oracleenterprise_manager_for_virtualization
oracleenterprise_manager_for_virtualization
oraclefinancial_services_analytical_applications_infrastructure

Detection & IOCsextracted from sources · hover to see the quote

otherorg.slf4j.ext (slf4j-ext class)
urlhttps://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44
  • Monitor for polymorphic deserialization attempts referencing slf4j-ext classes (e.g., `org.slf4j.ext`) in JSON payloads processed by jackson-databind 2.x before 2.9.7.
  • Look for `@class`, `@type`, or `@JsonTypeInfo`-driven JSON fields containing slf4j-ext class names as indicators of exploitation attempts against vulnerable jackson-databind instances.
  • Track the upstream patch commit (87d29af25e82a249ea15858e2d4ecbf64091db44) to confirm whether deployed jackson-databind versions include the slf4j-ext blocklist fix.
  • ·Applications that use only a patched version of slf4j (fixing CVE-2018-8088) are not vulnerable, even if running a vulnerable jackson-databind version, because the underlying slf4j-ext gadget is neutralized.
  • ·Deployments that do not bundle or use the slf4j-ext JAR are not vulnerable regardless of jackson-databind version.
  • ·Even though slf4j is part of OpenDaylight-parent aggregator, the versions included are not vulnerable, and specifically the slf4j-ext library is not in use — illustrating that presence of slf4j alone is insufficient; slf4j-ext must be on the classpath.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.