<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CVE-2019-17267 - FasterXML Jackson-databind in Esri Software Security &amp; Privacy Questions</title>
    <link>https://community.esri.com/t5/esri-software-security-privacy-questions/cve-2019-17267-fasterxml-jackson-databind/m-p/1306557#M149</link>
    <description>&lt;P&gt;If your IA team needs an artifact, they can look this up in our 3rd party CVE response tool. It's in the customer exclusive documents are in the ArcGIS Trust Center.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jul 2023 15:27:37 GMT</pubDate>
    <dc:creator>RandallWilliams</dc:creator>
    <dc:date>2023-07-07T15:27:37Z</dc:date>
    <item>
      <title>CVE-2019-17267 - FasterXML Jackson-databind</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/cve-2019-17267-fasterxml-jackson-databind/m-p/1306552#M147</link>
      <description>&lt;P&gt;Our IT department came across&amp;nbsp;CVE-2019-17267 related to fasterxml jackson-databind and believe it is linked to GeoEvent Server.&amp;nbsp; This also shows up in our dev environment, ArcGIS Server, and ArcGIS for Portal environments.&amp;nbsp; I should also note we no longer use GeoEvent Server.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has there been any patches or updates to address this CVE?&amp;nbsp; Is it safe to mark this as an exception?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 15:22:39 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/cve-2019-17267-fasterxml-jackson-databind/m-p/1306552#M147</guid>
      <dc:creator>ToddCopeland</dc:creator>
      <dc:date>2023-07-07T15:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2019-17267 - FasterXML Jackson-databind</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/cve-2019-17267-fasterxml-jackson-databind/m-p/1306556#M148</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Jackson deserialization issues are not exploitable in the Enterprise base enterprise deployment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In general, if you're not using a given service like Geoevent, you should disable the Geoevent service or uninstall it so that you limit the potential attack surface - but the Jackson-Databind dependency is in ArcGIS Server as well. It'd brought in as a dependency upon dependency of other 3rd party frameworks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 15:29:58 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/cve-2019-17267-fasterxml-jackson-databind/m-p/1306556#M148</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2023-07-07T15:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2019-17267 - FasterXML Jackson-databind</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/cve-2019-17267-fasterxml-jackson-databind/m-p/1306557#M149</link>
      <description>&lt;P&gt;If your IA team needs an artifact, they can look this up in our 3rd party CVE response tool. It's in the customer exclusive documents are in the ArcGIS Trust Center.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 15:27:37 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/cve-2019-17267-fasterxml-jackson-databind/m-p/1306557#M149</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2023-07-07T15:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2019-17267 - FasterXML Jackson-databind</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/cve-2019-17267-fasterxml-jackson-databind/m-p/1306686#M150</link>
      <description>&lt;P&gt;Thank you for the update &lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/2892"&gt;@RandallWilliams&lt;/a&gt;.&amp;nbsp; I'll pass along the information to IT and let you know if we have any further questions.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 20:45:34 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/cve-2019-17267-fasterxml-jackson-databind/m-p/1306686#M150</guid>
      <dc:creator>ToddCopeland</dc:creator>
      <dc:date>2023-07-07T20:45:34Z</dc:date>
    </item>
  </channel>
</rss>

