Back to search
CVE-2017-18349
Published: Oct 23, 2018
Modified: Sep 17, 2024
PUBLISHED
Description
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://fortiguard.com/encyclopedia/ips/44059
x_refsource_MISC
https://github.com/pippo-java/pippo/issues/466
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now