Overview Recently, NSFOCUS CERT detected that a Fastjson 1.2.x remote code execution vulnerability without gadget was disclosed online; Due to the defects in the internal type parsing logic of Fastjson deserialization, unauthenticated attackers can construct specially crafted malicious JSON data to bypass the traditional autoType black and white list protection...
