QID 981234
QID 981234: Java (maven) Security Update for ro.pippo:pippo-core (GHSA-7fm6-2qw4-g3x3)
An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the object types. An attacker can create a malicious object, base64 encode it, and place it in the PIPPO_SESSION field of a cookie. Sending this cookie may lead to remote code execution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7fm6-2qw4-g3x3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-7fm6-2qw4-g3x3 -
github.com/advisories/GHSA-7fm6-2qw4-g3x3
CVEs related to QID 981234
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7fm6-2qw4-g3x3 | ro.pippo:pippo-core |
|