QID 980789
QID 980789: Java (maven) Security Update for com.alibaba:fastjson (GHSA-xjrr-xv9m-4pw5)
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xjrr-xv9m-4pw5 for updates pertaining to this vulnerability.
Vendor References
- GHSA-xjrr-xv9m-4pw5 -
github.com/advisories/GHSA-xjrr-xv9m-4pw5
CVEs related to QID 980789
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xjrr-xv9m-4pw5 | com.alibaba:fastjson |
|