logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2017-7525

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2017-7525

Description:
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
Last updated date:
06/08/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
12/04/2017
Reference url to background

https://github.com/SecureSkyTechnology/study-struts2-s2-054_055-jackson-cve-2017-7525_cve-2017-15095

Type:
exploit
Confidence:
HIGH
Date of publishing:
01/22/2019
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/22/2020
Type:
exploit
Confidence:
HIGH
Date of publishing:
06/26/2020
Reference url to background

https://www.secfree.com/article-617.html

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy