Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-25845

The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.903
EPSS Ranking 99.6%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 6.8
References
Products affected by CVE-2022-25845


Contact Us

Shodan ® - All rights reserved