GHSA-pv7h-hx5h-mgfj
Dashboard / Vulnerabilities / GHSA-pv7h-hx5h-mgfj
GHSA-pv7h-hx5h-mgfj
Summary: Unsafe deserialization in com.alibaba:fastjson
Details: The package com.alibaba:fastjson before 1.2.83 is vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).
References: https://nvd.nist.gov/vuln/detail/CVE-2022-25845, https://github.com/alibaba/fastjson/commit/35db4adad70c32089542f23c272def1ad920a60d, https://github.com/alibaba/fastjson/commit/8f3410f81cbd437f7c459f8868445d50ad301f15, https://github.com/alibaba/fastjson, https://github.com/alibaba/fastjson/releases/tag/1.2.83, https://github.com/alibaba/fastjson/wiki/security_update_20220523, https://snyk.io/vuln/SNYK-JAVA-COMALIBABA-2859222, https://www.ddosi.org/fastjson-poc, https://www.oracle.com/security-alerts/cpujul2022.html
Affected packages
Package
Name: com.alibaba:fastjson
Purl: pkg:maven/com.alibaba/fastjson
Affected ranges
Type: ECOSYSTEM
Events:
