CVE-2017-7525 is an unsafe deserialization vulnerability in FasterXML jackson-databind's polymorphic deserialization handling. Maliciously crafted input processed by ObjectMapper.readValue can cause instantiation of attacker-selected types and invocation of usable deserialization gadget chains, potentially resulting in arbitrary code execution. The issue affects jackson-databind releases before 2.6.7.1, 2.7.9.1, and 2.8.9 in their respective release lines. The initial remediation restricted known dangerous types using a blacklist; later CVEs identified bypasses and additional gadget classes.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a comprehensive research and proof-of-concept (PoC) suite for demonstrating and testing the exploitation of Jackson-databind deserialization vulnerabilities (CVE-2017-7525 and CVE-2017-15095), as well as their impact on Apache Struts2 REST plugin (notably S2-054 and S2-055). The repository contains: - Multiple Groovy scripts (e.g., cve-2017-7525-poc.groovy, cve-2017-7525-check.groovy, cve-2017-15095-check.groovy) that demonstrate how to exploit or check for the vulnerabilities in different versions of Jackson-databind. The PoC script crafts a malicious JSON payload that attempts to instantiate a dangerous class (TemplatesImpl) with attacker-controlled bytecode, which can lead to remote code execution if deserialized by a vulnerable ObjectMapper with default typing enabled. - A full Java web application (rest-showcase) based on Apache Struts2 REST plugin, with source code for controllers, services, and models, as well as configuration files (struts.xml, web.xml) and JSP templates. This application is used to demonstrate the real-world impact of the vulnerabilities in a Struts2 context. - Test cases and utilities for interacting with the REST endpoints, including posting JSON and XML data to simulate attacks. The main exploit vector is network-based, targeting web applications that accept and deserialize untrusted JSON input using a vulnerable Jackson-databind configuration. The repository is structured to both educate about the vulnerabilities and provide working PoC code for security testing and research.
This repository is a demonstration exploit and vulnerable web application for the Jackson-databind remote code execution vulnerability (CVE-2017-7525). It consists of a Java Spring Boot backend and an Angular frontend. The backend exposes several API endpoints (notably /api/files/upload, /api/list, and /api/users) that process user-supplied JSON or file uploads using Jackson-databind with default typing enabled, making them vulnerable to deserialization attacks. The provided payload (see docs/test-exploit.json) leverages the FileSystemXmlApplicationContext gadget to load a remote XML file (docs/spel.xml), which can trigger arbitrary code execution (e.g., launching calc.exe). The frontend provides forms and file upload interfaces to interact with these endpoints. The repository is structured as a full-stack demo, with clear separation between backend and frontend code, and includes example payloads and documentation for testing the exploit. The exploit is a proof-of-concept and does not include weaponized or automated payload generation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
67 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Jackson Databind deserialization vulnerability in ObjectMapper.readValue.
A Jackson Databind deserialization flaw in ObjectMapper.readValue.
A prior Jackson-databind unsafe-deserialization vulnerability referenced as having received incomplete follow-on fixes.
A prior Jackson-databind vulnerability referenced because subsequent incomplete fixes failed to fully remediate its unsafe deserialization risk.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.