SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-25845

The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions.

CRITICAL 9.8EPSS 18.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 18.7%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
18.74% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-502
Affected
alibaba/fastjson · oracle/communications cloud native core unified data repository
Source
report@snyk.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.