PT-2018-3325 · Fasterxml+1 · Jackson-Databind+1

CVE-2018-5968

·

Published

2018-01-21

·

Updated

2026-08-24

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions jackson-databind (affected versions not specified)
Description The issue is related to weaknesses in the deserialization mechanism of the jackson-databind library. Exploitation of this issue may allow a remote attacker to execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Deserialization of Untrusted Data

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1722
BDU:2019-04797
CVE-2018-5968
DSA-4114-1
GHSA-W3F4-3Q6J-RH82
MGASA-2018-0138
RHSA-2018:0479
RHSA-2018:0480
RHSA-2018:0481
RHSA-2018:1525

Affected Products

Alt Linux
Jackson-Databind