Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25845

Опубликовано: 10 июн. 2022
Источник: redhat
CVSS3: 8.1
EPSS Высокий

Описание

The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable safeMode.

A flaw was found in com.alibaba:fastjson, a fast JSON parser/generator for Java. Affected versions of this package are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions.

Меры по смягчению последствий

Users who can not upgrade to the fixed version may enable safeMode; this completely disables the autoType function and eliminates the vulnerability risk. [https://github.com/alibaba/fastjson/wiki/fastjson_safemode]

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Integration Camel K 1fastjsonAffected
Red Hat Integration Camel Quarkus 1fastjsonAffected
Red Hat Integration Data Virtualisation OperatorfastjsonOut of support scope
Red Hat OpenShift Application RuntimesfastjsonNot affected
Red Hat Fuse 7.11fastjsonFixedRHSA-2022:553207.07.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2100654fastjson: autoType shutdown restriction bypass leads to deserialization

EPSS

Процентиль: 99%
0.86906
Высокий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
больше 3 лет назад

The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).

CVSS3: 8.1
github
больше 3 лет назад

Unsafe deserialization in com.alibaba:fastjson

CVSS3: 9.8
fstec
почти 4 года назад

Уязвимость механизма AutoTypeCheck библиотеки языка программирования Java Fastjson, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 99%
0.86906
Высокий

8.1 High

CVSS3