CVE-2022-25845
HIGHAlibaba Fastjson < 1.2.83 - Insecure Deserialization
Title source: ruleDescription
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).
Exploits (7)
nomisec
WORKING POC
106 stars
by luelueking · poc
https://github.com/luelueking/CVE-2022-25845-In-Spring
github
WORKING POC
5 stars
by JAckLosingHeart · javapoc
https://github.com/JAckLosingHeart/CVE-PoC-Collection/tree/main/fastjson-CVE-2022-25845
nomisec
WORKING POC
1 stars
by nerowander · poc
https://github.com/nerowander/CVE-2022-25845-exploit
References (7)
Scores
CVSS v3
8.1
EPSS
0.8857
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (3)
alibaba/fastjson
< 1.2.83
oracle/communications_cloud_native_core_unified_data_repository
com.alibaba/fastjson
< 1.2.83Maven
Timeline
Published
Jun 10, 2022
Tracked Since
Feb 18, 2026