VDB
KO
CRITICAL 9.0

GHSA-crf3-v9rr-v7hj

fastjson has a remote code execution (RCE) vulnerability

Details

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven / com.alibaba:fastjson
Introduced in: 1.2.68

No fixed version published yet for com.alibaba:fastjson (maven). Pin to a known-safe version or switch to an alternative.

References