CVE-2017-7525
CRITICAL 9.8EPSS 37.7%
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 37.72% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2018-02-06
- Updated
- 2024-09-17
Proof-of-concept exploits (15)
- Dannners/jackson-deserialization-2017-75251★ · 2023-03-28
- JavanXD/Demo-Exploit-Jackson-RCE18★ · 2019-02-21
- Nazicc/S2-0550★ · 2017-12-18
- SecureSkyTechnology/study-struts2-s2-054_055-jackson-cve-2017-7525_cve-2017-15095106★ · 2017-12-13
- ShiftLeftSecurity/HelloShiftLeft-Scala1★ · 2025-09-05
- atul-joshi-aera/jackson-2017-75250★ · 2024-10-16
- boonyashka/scala0★ · 2025-09-10
- conikeec/helloshiftleftplay0★ · 2020-01-10
- galimba/Jackson-deserialization-PoC8★ · 2020-08-03
- hdgittest/HelloShiftLeft-Scala0★ · 2025-04-24
- hdgittest/HelloshiftLeft_scala0★ · 2025-04-23
- irsl/jackson-rce-via-spel121★ · 2018-01-09
- jault3/jackson-databind-exploit13★ · 2019-03-22
- ongamse/Scala0★ · 2025-05-14
- wahyuhadi/spel.xml0★ · 2023-03-28