Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict unmarshalling.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pippo 代码问题漏洞
Vulnerability Description
Pippo是一款基于Java的Web框架。 Pippo 1.11.0及之前版本中存在安全漏洞,该漏洞源于XstreamEngine组件没有使用XStream可用的防御机制来限制反编组。远程攻击者可通过向java.lang.ProcessBuilder发送命令利用该漏洞执行代码。
CVSS Information
N/A
Vulnerability Type
N/A