Vulnerability GHSA-xjrr-xv9m-4pw5

Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
7 years ago
October 24, 2018 at 07:42 PM UTC
Improper Input Validation in alilibaba:fastjson
1.1.32 - 1.1.34 and 1.1.42 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.30
1.1.32 - 1.1.34 and 1.1.42 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.30

Summary

Improper Input Validation in alilibaba:fastjson

Details

parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.

Timeline

Published
7 years ago
October 24, 2018 at 07:42 PM UTC
Fixed (1.2.31)
Unknown
Unknown
Fixed (1.12.0)
Unknown
Unknown
Last Modified
2 years ago
February 16, 2024 at 07:59 AM UTC