Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Remote Code Execution in fastjson 1.2.68–1.2.83
Vulnerability Description
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
输入验证不恰当
Vulnerability Title
Alibaba FASTJSON 2 输入验证错误漏洞
Vulnerability Description
Alibaba Fastjson是中国Alibaba公司开源的一款基于Java的快速JSON解析器/生成器。 Alibaba FASTJSON 2 1.2.68版本至1.2.83版本存在安全漏洞,该漏洞源于输入验证错误和反序列化注入问题,在默认配置下无需启用AutoType或classpath gadget即可被利用,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A