Fastjson 2.x Remote Code Execution Vulnerability Notice

Overview Recently, NSFOCUS CERT detected that a Fastjson 2.x remote code execution vulnerability was disclosed online; Because Fastjson2.x may still handle @type in JSON through the built-in whitelist when SupportAutoType is not enabled by default configuration, an unauthenticated attacker can construct specially crafted malicious JSON data and achieve remote code...

NSFOCUS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.