The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2022-06-10T20:05:40.814063Z

Updated: 2024-09-16T23:36:49.600Z

Reserved: 2022-02-24T00:00:00

Link: CVE-2022-25845

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-06-10T20:15:08.117

Modified: 2023-02-23T17:51:57.970

Link: CVE-2022-25845

cve-icon Redhat

Severity : Important

Publid Date: 2022-06-10T00:00:00Z

Links: CVE-2022-25845 - Bugzilla