CVE-2022-25845

HIGH

Alibaba Fastjson < 1.2.83 - Insecure Deserialization

Title source: rule

Description

The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).

Exploits (7)

nomisec WORKING POC 106 stars
by luelueking · poc
https://github.com/luelueking/CVE-2022-25845-In-Spring
nomisec WORKING POC 91 stars
by hosch3n · poc
https://github.com/hosch3n/FastjsonVulns
nomisec WORKING POC 7 stars
by ph0ebus · poc
https://github.com/ph0ebus/CVE-2022-25845-In-Spring
github WORKING POC 5 stars
by JAckLosingHeart · javapoc
https://github.com/JAckLosingHeart/CVE-PoC-Collection/tree/main/fastjson-CVE-2022-25845
nomisec WORKING POC 1 stars
by nerowander · poc
https://github.com/nerowander/CVE-2022-25845-exploit
nomisec WORKING POC
by cuijiung · poc
https://github.com/cuijiung/fastjson-CVE-2022-25845
nomisec WORKING POC
by scabench · poc
https://github.com/scabench/fastjson-tp1fn1

Scores

CVSS v3 8.1
EPSS 0.8857
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (3)

alibaba/fastjson < 1.2.83
oracle/communications_cloud_native_core_unified_data_repository
com.alibaba/fastjson < 1.2.83Maven

Timeline

Published Jun 10, 2022
Tracked Since Feb 18, 2026