Vulnerability GHSA-xjrr-xv9m-4pw5
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
7 years ago
October 24, 2018 at 07:42 PM UTC
Improper Input Validation in alilibaba:fastjson
1.1.32 - 1.1.34 and 1.1.42 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.30
1.1.32 - 1.1.34 and 1.1.42 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.30
Summary
Improper Input Validation in alilibaba:fastjson
Details
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
2 months ago
fastjson has a remote code execution (RCE) vulnerability
1.2.68 - 1.2.72 and 1.2.83 GHSA-crf3-v9rr-v7hj
1.2.68 - 1.2.72 and 1.2.83 GHSA-crf3-v9rr-v7hj
Critical
8 months ago
FASTJSON Includes Functionality from Untrusted Control Sphere
1.1.32 - 1.1.34 and 1.1.42 - 1.1.46 and 1.2.3 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.31 GHSA-jm7w-5684-pvh8
1.1.32 - 1.1.34 and 1.1.42 - 1.1.46 and 1.2.3 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.31 GHSA-jm7w-5684-pvh8
High Risk
4 years ago
Unsafe deserialization in com.alibaba:fastjson
1.2.25 - 1.2.31 and 1.2.49 - 1.2.62 and 1.2.66 - 1.2.72 GHSA-pv7h-hx5h-mgfj
1.2.25 - 1.2.31 and 1.2.49 - 1.2.62 and 1.2.66 - 1.2.72 GHSA-pv7h-hx5h-mgfj
Impacted packages
Timeline
Published
7 years ago
October 24, 2018 at 07:42 PM UTC
Fixed (1.2.31)
Unknown
Unknown
Fixed (1.12.0)
Unknown
Unknown
Last Modified
2 years ago
February 16, 2024 at 07:59 AM UTC