Alibaba fastJSON 1.2.29

CPE Details

Alibaba fastJSON 1.2.29
1.2.29
2019-07-29
10h39 +00:00
2019-07-29
10h39 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:alibaba:fastjson:1.2.29:*:*:*:*:*:*:*

Informations

Vendor

alibaba

Product

fastjson

Version

1.2.29

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-25845 2022-06-10 20h05 +00:00 The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).
9.8
Critical