Unsafe deserialization in com.alibaba:fastjson
High severity
GitHub Reviewed
Published
Jun 11, 2022
to the GitHub Advisory Database
•
Updated May 15, 2024
Description
Published by the National Vulnerability Database
Jun 10, 2022
Published to the GitHub Advisory Database
Jun 11, 2022
Reviewed
Jun 17, 2022
Last updated
May 15, 2024
The package com.alibaba:fastjson before 1.2.83 is vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable safeMode.
References