IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.
References
Link | Resource |
---|---|
http://breeze.github.io/doc-net/release-notes.html | Release Notes Vendor Advisory |
https://www.blackhat.com/us-17/briefings.html#friday-the-13th-json-attacks | Technical Description |
Configurations
History
No history.
Information
Published : 2017-06-22 16:29
Updated : 2024-02-28 16:04
NVD link : CVE-2017-9424
Mitre link : CVE-2017-9424
CVE.ORG link : CVE-2017-9424
JSON object : View
Products Affected
ideablade
- breeze.server.net
CWE
CWE-502
Deserialization of Untrusted Data