Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Block two more gadgets to exploit default typing issue (c3p0, CVE-2018-7489) #1931

Closed
cowtowncoder opened this issue Feb 11, 2018 · 15 comments
Closed
Labels
CVE Issues related to public CVEs (security vuln reports)
Milestone

Comments

@cowtowncoder
Copy link
Member

cowtowncoder commented Feb 11, 2018

From an email report there are 2 other c3p0 classes (above and beyond ones listed in #1737) need to be blocked.

EDIT 21-Jun-2021: Fix included in:

  • 2.9.5
  • 2.8.11.1
  • 2.7.9.3
  • 2.6.7.5
@cowtowncoder cowtowncoder added 2.8 CVE Issues related to public CVEs (security vuln reports) labels Feb 11, 2018
@cowtowncoder cowtowncoder changed the title Two c3p0 gadgets to exploit default typing issue Two more c3p0 gadgets to exploit default typing issue Feb 11, 2018
@cowtowncoder
Copy link
Member Author

Fixed in 2.8.11.1 (newly released) and 2.9.5 (when it is released)

@philippn
Copy link

Hi there!
How comes that there is no atifact in http://repo1.maven.org/maven2/com/fasterxml/jackson/jackson-bom/ that is matching release 2.8.11.1?

This is preventing me from upgrading to 2.8.11.1 because that artifact would be required by Spring boots dependency management.

Thanks in advance!

@cowtowncoder
Copy link
Member Author

@philippn Because beyond 2.8.11.1 there is no full release, and it is not really practical to create one-off bom sets: there may or may not be micro-patches for various components.

What you need to do is to either use 2.8.11 bom and overrides (re-define one of version properties) or add explicit direct dependency. Alternatively you could probably build a separate bom of your own, one that extends jackson-bom-2.8.11.

@philippn
Copy link

Thanks for the clarification!

@cowtowncoder
Copy link
Member Author

@philippn np. And apologies for the mess. I understand it is not ideal, and I am hoping we can figure out a more maintainable system for CVE updates.

@cowtowncoder
Copy link
Member Author

@cowtowncoder cowtowncoder changed the title Two more c3p0 gadgets to exploit default typing issue Two more c3p0 gadgets to exploit default typing issue [CVE-2018-7489] Mar 2, 2018
@cowtowncoder
Copy link
Member Author

@aiannucci
Copy link

Hi! Any estimates for a 2.9.5 release? Thanks!

@DKumars
Copy link

DKumars commented Mar 26, 2018

Hi FasterXML Team ,
As new vulnerability CVE-2018-7489 is reported and we are using jackson-databind 2.9.4 version which is now vulnerable. Please confirm us when we can get full new release like 2.9.5 or patch fix in v2.9.4.1 which will help to get rid of this vulnerability.

-thanks
Dharmendra

@kiranmn
Copy link

kiranmn commented Apr 6, 2018

Is this defect applicable for org.codehaus.jackson libraries too?

@cowtowncoder cowtowncoder changed the title Two more c3p0 gadgets to exploit default typing issue [CVE-2018-7489] Block two more gadgets to exploit default typing issue (c3p0, CVE-2018-7489) Sep 12, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CVE Issues related to public CVEs (security vuln reports)
Projects
None yet
Development

No branches or pull requests

6 participants