QID 981234

QID 981234: Java (maven) Security Update for ro.pippo:pippo-core (GHSA-7fm6-2qw4-g3x3)

An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the object types. An attacker can create a malicious object, base64 encode it, and place it in the PIPPO_SESSION field of a cookie. Sending this cookie may lead to remote code execution.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to refer to GHSA-7fm6-2qw4-g3x3 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981234

    Software Advisories
    Advisory ID Software Component Link
    GHSA-7fm6-2qw4-g3x3 ro.pippo:pippo-core URL Logo github.com/advisories/GHSA-7fm6-2qw4-g3x3