Deserialization of Untrusted Datacom.alibaba:fastjson is a fast JSON parser/generator for Java.
Affected versions of this package are vulnerable to Deserialization of Untrusted Data through the JSON parsing path in JSON.parse, JSON.parseObject(String), and JSON.parseObject(String, Class) when it runs inside a Spring Boot executable fat-jar. An attacker can execute code by supplying crafted JSON that reaches the vulnerable type-resolution logic, including nested payloads in Object or Map fields. The issue affects applications using the stock default configuration, and it can let a remote attacker run arbitrary code in the process that deserializes the JSON.
Notes
- The vulnerable path is verified only in Spring Boot executable fat-jar deployments started with
java -jar; plain classpath launches and WAR-style deployments are outside the documented trigger condition.
- The issue is present under fastjson’s stock defaults with
AutoType and SafeMode both off; enabling SafeMode blocks the vulnerable @type handling before this path is reached.
Workarounds
- Enable
SafeMode by setting -Dfastjson.parser.safeMode=true, calling ParserConfig.getGlobalInstance().setSafeMode(true), or configuring it in fastjson.properties; this blocks @type-based payloads before they reach the vulnerable parsing path.
- Switch to a
noneautotype build such as com.alibaba:fastjson:1.2.83_noneautotype; this removes the vulnerable code path from the deployed artifact.
- Migrate to
fastjson2; this avoids the vulnerable fastjson 1.x parsing behavior in affected deployments.
How to fix Deserialization of Untrusted Data? Upgrade com.alibaba:fastjson to version 1.2.84 or higher.
| |
Deserialization of Untrusted Datacom.alibaba:fastjson is a fast JSON parser/generator for Java.
Affected versions of this package are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers.
How to fix Deserialization of Untrusted Data? Upgrade com.alibaba:fastjson to version 1.2.83 or higher.
| |