VendorsAlibabafastjsonall versions
Vulnerabilities

Alibaba fastJSON

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2017-18349
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.
Published 2018-10-23 · Modified
10.0EPSS 0.392
CVE-2022-25845
Deserialization of Untrusted Data
Published 2022-06-10 · Modified
9.8EPSS 0.187