A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
PoC: study-struts2-s2-054_055-jackson-cve-2017-7525_cve-2017-15095
Struts2の脆弱性S2-045, S2-055 および Jackson の脆弱性 CVE-2017-7525, CVE-2017-15095 の調査報告
PoC: Demo-Exploit-Jackson-RCE
Exploiting CVE-2017-7525 demo project with Angular7 frontend and Spring.
PoC: CVE-2017-7525-Jackson-Deserialization-Lab
Insecure Java Deserialization Lab
PoC: jackson-deserialization-2017-7525
Jackson Deserialization CVE-2017-7525 PoC
PoC: S2-055
CVE-2017-7525 S2-055 Exploit
PoC: jackson-RCE
Demo for CVE-2017-7525
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free