CVE-2022-25845
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.7%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 18.74% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- alibaba/fastjson · oracle/communications cloud native core unified data repository
- Source
- report@snyk.io
References
- https://github.com/alibaba/fastjson/commit/35db4adad70c32089542f23c272def1ad920a60dPatch, Third Party Advisory
- https://github.com/alibaba/fastjson/commit/8f3410f81cbd437f7c459f8868445d50ad301f15Patch, Third Party Advisory
- https://github.com/alibaba/fastjson/releases/tag/1.2.83Release Notes, Third Party Advisory
- https://github.com/alibaba/fastjson/wiki/security_update_20220523Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-COMALIBABA-2859222Third Party Advisory
- https://www.ddosi.org/fastjson-poc/Exploit, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://github.com/alibaba/fastjson/commit/35db4adad70c32089542f23c272def1ad920a60dPatch, Third Party Advisory
- https://github.com/alibaba/fastjson/commit/8f3410f81cbd437f7c459f8868445d50ad301f15Patch, Third Party Advisory
- https://github.com/alibaba/fastjson/releases/tag/1.2.83Release Notes, Third Party Advisory
- https://github.com/alibaba/fastjson/wiki/security_update_20220523Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-COMALIBABA-2859222Third Party Advisory
- https://www.ddosi.org/fastjson-poc/Exploit, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.