CVE-2022-25845
Last modified
CVE-2022-25845 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. EPSS estimates a 17.77% chance of exploitation in the next 30 days.
Description
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alibaba | Fastjson | < 1.2.83 |
| Oracle | Communications Cloud Native Core Unified Data Repository | 22.2.0 |
References
- https://github.com/alibaba/fastjson/commit/35db4adad70c32089542f23c272def1ad920a60dPatch, Third Party Advisory
- https://github.com/alibaba/fastjson/commit/8f3410f81cbd437f7c459f8868445d50ad301f15Patch, Third Party Advisory
- https://github.com/alibaba/fastjson/releases/tag/1.2.83Release Notes, Third Party Advisory
- https://github.com/alibaba/fastjson/wiki/security_update_20220523Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-COMALIBABA-2859222Third Party Advisory
- https://www.ddosi.org/fastjson-poc/Exploit, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://github.com/alibaba/fastjson/commit/35db4adad70c32089542f23c272def1ad920a60dPatch, Third Party Advisory
- https://github.com/alibaba/fastjson/commit/8f3410f81cbd437f7c459f8868445d50ad301f15Patch, Third Party Advisory
- https://github.com/alibaba/fastjson/releases/tag/1.2.83Release Notes, Third Party Advisory
- https://github.com/alibaba/fastjson/wiki/security_update_20220523Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-COMALIBABA-2859222Third Party Advisory
- https://www.ddosi.org/fastjson-poc/Exploit, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-25845?
How severe is CVE-2022-25845?
How do I fix CVE-2022-25845?
Are you affected by CVE-2022-25845?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
