Hi ,Have a Good Day , we are using the atlassian/jira-software:8.9 image from hub.Docker.com in our Env
We found some vulnerabilities while scanning the image through Atrifactory X-ray scanner
FasterXML jackson-databind before 2.7.9.3, 2.8.x
before 2.8.11.1 and 2.9.x before 2.9.5 allows
unauthenticated remote code execution because of
an incomplete fix for the CVE-2017-7525
deserialization flaw. This is exploitable by sending
maliciously crafted JSON input to the readValue
method of the ObjectMapper, bypassing a blacklist
that is ineffective if the c3p0 libraries are available
in the classpath.
High security JFrog com.fasterxml.jackson.core:ja
ckson-databind
< 2.7.9.3,2.8.0 <= Version <
2.8.11.1,2.9.0.pr1 <= Version < 2.9.5
Fixed version = 2.9.5,2.8.11.1,2.7.9.3 2020-08-11T02:11:
29-05:00
High
https://nvd.nist.gov/vuln/detail/CVE-2017-7525