Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Fastjson rce vuln #2

Closed
xqc2000 opened this issue Nov 2, 2018 · 1 comment
Closed

Fastjson rce vuln #2

xqc2000 opened this issue Nov 2, 2018 · 1 comment

Comments

@xqc2000
Copy link

xqc2000 commented Nov 2, 2018

The component FastjsonEngine converts a JSON string to an equivalent Java Object based on Fastjson(version 1.2.11);
However,Fastjson version 1.2.24 and prior has a remote code execution vulnerability.
for details,please refer to the links below:
https://fortiguard.com/encyclopedia/ips/44059
http://xxlegend.com/2017/12/06/基于JdbcRowSetImpl的Fastjson%20RCE%20PoC构造与分析/
Upgrade to Fastjson version 1.2.45 or later can fix the issue.

@zycgit
Copy link
Collaborator

zycgit commented Dec 9, 2019

tks ,at new version Fastjson has been upgraded.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants