CVE-2017-18349
9.8
CRITICAL · CVSS 3.0 · EPSS 39.2% (pctl 99)
Patch early
EPSS 39.2% — above the 10% action threshold.
Description
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 39.24% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-10-23 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| alibaba | fastjson |
| pippo | pippo |
References
- https://fortiguard.com/encyclopedia/ips/44059
- https://github.com/alibaba/fastjson/wiki/security_update_20170315
- https://github.com/pippo-java/pippo/issues/466
- https://fortiguard.com/encyclopedia/ips/44059
- https://github.com/alibaba/fastjson/wiki/security_update_20170315
- https://github.com/pippo-java/pippo/issues/466
→ the Explorer · watch your stack · NVD