CVE-2018-5968: Debian Linux
High severity, CVSS 8.1. EPSS: 7.2% chance of exploitation in the next 30 days.
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Fasterxml Jackson-Databind: from 2.0.0, before 2.6.7.3 (fixed in 2.6.7.3); from 2.7.0, before 2.7.9.2 (fixed in 2.7.9.2); from 2.8.0, before 2.8.11.1 (fixed in 2.8.11.1); from 2.9.0, before 2.9.4 (fixed in 2.9.4)
- Netapp E-Series Santricity OS Controller: from 11.0.0, up to and including 11.60.3
- Netapp E-Series Santricity Web Services Proxy: affected versions not specified
- Netapp Oncommand Shift: affected versions not specified
- Red Hat JBoss Enterprise Application Platform: version 7.1 only
- Red Hat Openshift Container Platform: version 4.1 only; version 3.11 only
- Red Hat Virtualization: version 4.0 only
- Red Hat Virtualization Host: version 4.0 only
Published 2018-01-22. Last modified 2026-10-08.