Описание
An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the object types. An attacker can create a malicious object, base64 encode it, and place it in the PIPPO_SESSION field of a cookie. Sending this cookie may lead to remote code execution.
Ссылки
- ExploitPatchThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:pippo:pippo:1.11.0:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04385
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-502
Связанные уязвимости
EPSS
Процентиль: 89%
0.04385
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-502