Vulnerabilities in Jackson Databind 2.9.9 

Issue date: 28-08-2019
Affects versions: 13.3, 13.2, 12.6, 11.2

Issue ID: SECURITY-118

Affected Product Version(s)

This vulnerability affects all versions of both CMS and delivery applications based on Bloomreach Experience Manager prior to 11.2.15.1, 12.6.6, 13.2.2, and 13.3.0.


Severity 

Medium


Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

This vulnerability is classified with severity medium. Although default usage of this library within the Hippo CMS product is not vulnerable, project specific usages of the Jackson2 library within a Hippo CMS project may be vulnerable. 

The FasterXML jackson-databind version in all supported CMS maintenance versions 11.2.15.1, 12.6.6, 13.2.2, and 13.3.0 has been updated from 2.9.9 to 2.9.9.1.

 

Instructions

Every customer is strongly advised to upgrade as soon as possible to the latest maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.