← Back to browse · API

CVE-2017-17485

Severity
CRITICAL
CVSS
9.8
EPSS
0.49727
Risk score
56.6
CISA KEV
No
PoC
No
Published
2018-01-10
Modified
2025-08-27
First seen
2026-08-07
Aliases
EUVD-2018-0684, GHSA-RFX6-VP9G-RH7V
Products
n/a:n/a n/a
Sources
euvd EUVD-2018-0684

Description

FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.

References