CVE-2022-25845
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).
- Affected products
- Fastjson
- Alibaba Fastjson
- < 1.2.83
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 17.8% (97th percentile)
- Weakness
- CWE-502
- NVD status
- Modified
- Published
- 2022-06-10
CVE-2022-25845 at NVD
5 known exploits for CVE-2022-25845
Proof-of-concept code and exploit modules indexed by Sploitus