Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pv7h-hx5h-mgfj

Опубликовано: 11 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Unsafe deserialization in com.alibaba:fastjson

The package com.alibaba:fastjson before 1.2.83 is vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable safeMode.

Пакеты

Наименование

com.alibaba:fastjson

maven
Затронутые версииВерсия исправления

>= 1.2.25, < 1.2.83

1.2.83

EPSS

Процентиль: 99%
0.88373
Высокий

8.1 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.1
redhat
больше 3 лет назад

The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).

CVSS3: 8.1
nvd
больше 3 лет назад

The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).

CVSS3: 9.8
fstec
почти 4 года назад

Уязвимость механизма AutoTypeCheck библиотеки языка программирования Java Fastjson, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 99%
0.88373
Высокий

8.1 High

CVSS3

Дефекты

CWE-502