peter bassill · operator
$ cve CVE-2018-18628 JSON

CVE-2018-18628

9.8
CRITICAL · CVSS 3.0 · EPSS 5.5% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the object types. An attacker can create a malicious object, base64 encode it, and place it in the PIPPO_SESSION field of a cookie. Sending this cookie may lead to remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.48% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2018-10-23
Last modified2026-06-17

Affected (1)

VendorProduct
pippopippo

References

→ the Explorer  ·  watch your stack  ·  NVD