{"advisories":[{"id":"GHSA-xjrr-xv9m-4pw5","source":"ghsa","title":"Improper Input Validation in alilibaba:fastjson","url":"https://github.com/advisories/GHSA-xjrr-xv9m-4pw5"}],"cve":"CVE-2017-18349","epss":{"score":0.3924},"mitre":{"cpes":[],"created":"2018-10-23T20:00:00+00:00","description":"parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2017/18xxx/CVE-2017-18349.json","references":["https://fortiguard.com/encyclopedia/ips/44059","https://github.com/alibaba/fastjson/wiki/security_update_20170315","https://github.com/pippo-java/pippo/issues/466"],"title":null,"updated":"2024-09-17T00:02:21.255000+00:00","vendors":[],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:alibaba:fastjson:*:*:*:*:*:*:*:*","cpe:2.3:a:pippo:pippo:1.11.0:*:*:*:*:*:*:*"],"created":"2018-10-23T20:29:00.263000+00:00","description":"parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.","metrics":{"cvssV2_0":{"score":10.0,"vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C"},"cvssV3_0":{"score":9.8,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV3_1":{},"cvssV4_0":{}},"nvd_repo_path":"2017/CVE-2017-18349.json","references":["https://fortiguard.com/encyclopedia/ips/44059","https://github.com/alibaba/fastjson/wiki/security_update_20170315","https://github.com/pippo-java/pippo/issues/466"],"title":null,"updated":"2026-06-17T01:12:39.987000+00:00","vendors":["alibaba","alibaba$PRODUCT$fastjson","pippo","pippo$PRODUCT$pippo"],"weaknesses":["CWE-20"]},"opencve":{"changes":[],"cpes":{"data":["cpe:2.3:a:alibaba:fastjson:*:*:*:*:*:*:*:*","cpe:2.3:a:pippo:pippo:1.11.0:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2018-10-23T20:00:00+00:00","provider":"mitre"},"description":{"data":"parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":10.0,"vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C"},"provider":"nvd"},"cvssV3_0":{"data":{"score":9.8,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"nvd"},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.3924},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://fortiguard.com/encyclopedia/ips/44059","https://github.com/alibaba/fastjson/wiki/security_update_20170315","https://github.com/pippo-java/pippo/issues/466"],"providers":["mitre","nvd"]},"title":{"data":null,"provider":null},"updated":{"data":"2024-11-21T03:19:54.190000+00:00","provider":"nvd"},"vendors":{"data":["alibaba","alibaba$PRODUCT$fastjson","pippo","pippo$PRODUCT$pippo"],"providers":["nvd"]},"weaknesses":{"data":["CWE-20"],"providers":["nvd"]}}}