← Back to CVE List

CVE-2017-18349

Published: 2018-10-23T20:29Z
Last Modified: 2024-11-21T03:19Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt