Learn about CVE-2017-18349, a Fastjson vulnerability affecting Pippo 1.11.0. Remote attackers can execute arbitrary code via a crafted JSON request. Find mitigation steps and updates here.
Fastjson parseObject function vulnerability in Pippo 1.11.0
Understanding CVE-2017-18349
Fastjson vulnerability impacting Pippo 1.11.0
What is CVE-2017-18349?
The parseObject function in Fastjson, before version 1.2.25, allows remote attackers to execute arbitrary code. This vulnerability affects FastjsonEngine in Pippo 1.11.0 and related products. It can be triggered by a malicious JSON request with a crafted rmi:// URI in the dataSourceName field of an HTTP POST request to the /json URI in Pippo.
The Impact of CVE-2017-18349
Technical Details of CVE-2017-18349
Details of the vulnerability in Fastjson and Pippo
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from CVE-2017-18349
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates