EXECUTIVE SUMMARY:
Multiple security vulnerabilities have been identified in the jackson-databind library across various versions of the 2.x and 3.x release lines. These issues encompass Incorrect Authorization, Server-Side Request Forgery (SSRF), and Denial of Service (DoS). Successful exploitation of these flaws could allow attackers to bypass critical security controls to perform mass-assignment or privilege escalation, trigger unauthorized outbound DNS requests for internal network scanning, or cause application instability and crashes via resource exhaustion.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Multiple security vulnerabilities have been identified in the jackson-databind library across various versions of the 2.x and 3.x release lines. These issues encompass Incorrect Authorization, Server-Side Request Forgery (SSRF), and Denial of Service (DoS). Successful exploitation of these flaws could allow attackers to bypass critical security controls to perform mass-assignment or privilege escalation, trigger unauthorized outbound DNS requests for internal network scanning, or cause application instability and crashes via resource exhaustion.[emaillocker id="1283"]
The presence of these vulnerabilities poses a significant risk to data integrity and system availability, particularly for applications relying on Jackson for input validation and access control. Organizations face potential business disruptions from service outages and severe security incidents resulting from privilege escalation or unauthorized internal network access. Immediate attention is required to assess exposure and prevent exploitation of these authorization and logic flaws.
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-5gvw-p9qm-jgwh
https://github.com/advisories/GHSA-rcqc-6cw3-h962
https://github.com/advisories/GHSA-3wrr-7qpf-2prh
https://github.com/advisories/GHSA-5hh8-q8hv-fr38
https://github.com/advisories/GHSA-hgj6-7826-r7m5