CVE-2017-18349
Last modified
CVE-2017-18349 is a vulnerability of currently unknown severity. parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.. EPSS estimates a 38.97% chance of exploitation in the next 30 days.
Description
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alibaba | Fastjson | < 1.2.25 |
| Pippo | Pippo | 1.11.0 |
References
- https://fortiguard.com/encyclopedia/ips/44059Mitigation, Third Party Advisory
- https://github.com/alibaba/fastjson/wiki/security_update_20170315Mitigation, Third Party Advisory
- https://github.com/pippo-java/pippo/issues/466Exploit, Third Party Advisory
- https://fortiguard.com/encyclopedia/ips/44059Mitigation, Third Party Advisory
- https://github.com/alibaba/fastjson/wiki/security_update_20170315Mitigation, Third Party Advisory
- https://github.com/pippo-java/pippo/issues/466Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-18349?
How severe is CVE-2017-18349?
How do I fix CVE-2017-18349?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-18343The debug handler in Symfony before v2.7.33, 2.8.x before v2…
- CVE-2017-18344The timer_create syscall implementation in kernel/time/posix…
- CVE-2017-18345The Joomanager component through 2.0.0 for Joomla! has an ar…
- CVE-2017-18346SQL injection vulnerability in /wbg/core/_includes/authoriza…
- CVE-2017-18347Incorrect access control in RDP Level 1 on STMicroelectronic…4.6
- CVE-2017-18348Splunk Enterprise 6.6.x, when configured to run as root but …
- CVE-2017-1835Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-18350bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based b…5.9
- CVE-2017-18352Error reporting within Rendertron 1.0.0 allows reflected Cro…
- CVE-2017-18353Rendertron 1.0.0 includes an _ah/stop route to shutdown the …
- CVE-2017-18354Rendertron 1.0.0 allows for alternative protocols such as 'f…
- CVE-2017-18355Installed packages are exposed by node_modules in Rendertron…
Are you affected by CVE-2017-18349?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
