Description
IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.
References (2)
Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
http://breeze.github.io/doc-net/release-notes.html
Technical Description x_refsource_misc
https://www.blackhat.com/us-17/briefings.html#friday-the-13th-json-attacks
Scores
CVSS v3
9.8
EPSS
0.0274
EPSS Percentile
84.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-502
Status
published
Products (1)
ideablade/breeze.server.net
< 1.6.0
Published
Jun 22, 2017
Tracked Since
Feb 18, 2026