Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    4
    Critical Level Threats
    1
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-5442

    XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large amounts of heap memory is taken. Eventually, the JVM process will run out of memory. Otherwise, if the OS does not bound the memory on that process, memory will continue to be exhausted and will affect other processes on the system.

    Last Modified: Nov 21, 2024
    Published: Jun 12, 2019

    CVE-2018-20059

    jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.

    Last Modified: Nov 21, 2024
    Published: Dec 11, 2018

    CVE-2018-18628

    An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the object types. An attacker can create a malicious object, base64 encode it, and place it in the PIPPO_SESSION field of a cookie. Sending this cookie may lead to remote code execution.

    Last Modified: Nov 21, 2024
    Published: Oct 23, 2018

    CVE-2017-18349

    parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.

    Last Modified: Nov 21, 2024
    Published: Oct 23, 2018

    CVE-2018-18240

    Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict unmarshalling.

    Last Modified: Nov 21, 2024
    Published: Oct 11, 2018
    Items Per Page
    Pippo Vulnerabilities & Security CVEs | CVE-DB