The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).
References
Configurations
History
21 Nov 2024, 06:53
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 6.8
v3 : 8.1 |
References | () https://github.com/alibaba/fastjson/commit/35db4adad70c32089542f23c272def1ad920a60d - Patch, Third Party Advisory | |
References | () https://github.com/alibaba/fastjson/commit/8f3410f81cbd437f7c459f8868445d50ad301f15 - Patch, Third Party Advisory | |
References | () https://github.com/alibaba/fastjson/releases/tag/1.2.83 - Release Notes, Third Party Advisory | |
References | () https://github.com/alibaba/fastjson/wiki/security_update_20220523 - Third Party Advisory | |
References | () https://snyk.io/vuln/SNYK-JAVA-COMALIBABA-2859222 - Third Party Advisory | |
References | () https://www.ddosi.org/fastjson-poc/ - Exploit, Third Party Advisory | |
References | () https://www.oracle.com/security-alerts/cpujul2022.html - Patch, Third Party Advisory |
Information
Published : 2022-06-10 20:15
Updated : 2024-11-21 06:53
NVD link : CVE-2022-25845
Mitre link : CVE-2022-25845
CVE.ORG link : CVE-2022-25845
JSON object : View
Products Affected
alibaba
- fastjson
oracle
- communications_cloud_native_core_unified_data_repository
CWE
CWE-502
Deserialization of Untrusted Data