Vulnerability GHSA-pv7h-hx5h-mgfj

High Risk
HIGH RISK
CVSS Score: 8.1
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
4 years ago
June 11, 2022 at 12:00 AM UTC
Unsafe deserialization in com.alibaba:fastjson
1.2.25 - 1.2.31 and 1.2.49 - 1.2.62 and 1.2.66 - 1.2.72
1.2.25 - 1.2.31 and 1.2.49 - 1.2.62 and 1.2.66 - 1.2.72

Summary

Unsafe deserialization in com.alibaba:fastjson

Details

The package com.alibaba:fastjson before 1.2.83 is vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable safeMode.

Impacted packages

Timeline

Published
4 years ago
June 11, 2022 at 12:00 AM UTC
Fixed (1.2.83)
Unknown
Unknown
Last Modified
2 months ago
July 08, 2026 at 06:50 AM UTC