Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2017-17485 - incomplete fix for CVE-2017-7525 #1904

Closed
kennymacleod opened this issue Jan 21, 2018 · 2 comments
Closed

CVE-2017-17485 - incomplete fix for CVE-2017-7525 #1904

kennymacleod opened this issue Jan 21, 2018 · 2 comments

Comments

@kennymacleod
Copy link

CVE-2017-17485 has been reported as an "incomplete fix" for CVE-2017-7525, and is listed in the vulnerability databases as affecting all the way up to Jackson 2.9.3.

How hard will it be to rework the original fix to plug the gap?

@cowtowncoder
Copy link
Member

It would be easier to answer the question if you explained what the supposed incompletion is.

@cowtowncoder
Copy link
Member

Ok. CVE itself (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17485) points to #1855.
Term incomplete is vague given the context -- by definition any blacklists are always incomplete. No code changes occurred. Fix in 2.8.11, and once 2.9.4 gets out, there as well.

Also if you haven't read it yet, please read

https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062

to know under what condition this CVE is relevant. For most users it isn't, but some frameworks use Default Typing, under which is is applicable.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants