Multiple deserialization vulnerabilities in FasterXML Jackson2 databind 

Issue date: 26-04-2018
Affects versions: 12.2, 11.2, 10.2

Issue ID: SECURITY-49

Affected Product Version(s)
This vulnerability affects all versions of both CMS and delivery applications based on Hippo CMS prior to 12.3.0, 12.2.1, 11.2.7, and 10.2.11.

Severity 
high

Description

Several deserialization flaws were discovered in the jackson-databind module of FasterXML Jackson2, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input.  See: CVE-2017-7525CVE-2017-17485, and CVE-2018-5968.

This vulnerability is classified with severity high. Although default usage of this library within the Hippo CMS product is not vulnerable, project specific usages of the Jackson2 library within a Hippo CMS project may be vulnerable. 

The FasterXML Jackson2 version in all supported CMS maintenance versions 10.2.11, 11.2.7, 12.2.1, and 12.3.0 has been updated to 2.8.11, and the jackson-databind module has been upgraded to 2.8.11.1.

  • The version used in the 10.2 series was previously 2.4.6.
  • The version used in the 11.2 and 12.2 series was previously 2.8.8.

Instructions

Every CMS customer is strongly advised to upgrade as soon as possible to the latest CMS maintenance release as indicated above, or higher.

Because the upgrade for these CMS maintenance versions may require some additonal steps and verification, specific upgrade documentation is available to our customers for upgrading to version 10.2.11, 11.2.7, or to 12.2.1 and 12.3.0 (login required).