Sploitus

CVE-2022-25845

5 known exploits for CVE-2022-25845

The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).

Affected products
Fastjson
Alibaba Fastjson
< 1.2.83
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
17.8% (97th percentile)
Weakness
CWE-502
NVD status
Modified
Published
2022-06-10
CVE-2022-25845 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2022-25845

Proof-of-concept code and exploit modules indexed by Sploitus