Описание
ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.
Ссылки
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2025-10-08 (исключая)
cpe:2.3:a:kutangguo:ktg-mes:*:*:*:*:*:*:*:*
EPSS
Процентиль: 19%
0.00059
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 6.5
github
3 месяца назад
ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.
EPSS
Процентиль: 19%
0.00059
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-502