com.alibaba:fastjson@1.2.69_sec11

  • latest version

    2.0.65

  • latest non vulnerable version

  • first published

    14 years ago

  • latest version published

    1 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the com.alibaba:fastjson package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Deserialization of Untrusted Data

    com.alibaba:fastjson is a fast JSON parser/generator for Java.

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data through the JSON parsing path in JSON.parse, JSON.parseObject(String), and JSON.parseObject(String, Class) when it runs inside a Spring Boot executable fat-jar. An attacker can execute code by supplying crafted JSON that reaches the vulnerable type-resolution logic, including nested payloads in Object or Map fields. The issue affects applications using the stock default configuration, and it can let a remote attacker run arbitrary code in the process that deserializes the JSON.

    Notes

    • The vulnerable path is verified only in Spring Boot executable fat-jar deployments started with java -jar; plain classpath launches and WAR-style deployments are outside the documented trigger condition.
    • The issue is present under fastjson’s stock defaults with AutoType and SafeMode both off; enabling SafeMode blocks the vulnerable @type handling before this path is reached.

    Workarounds

    • Enable SafeMode by setting -Dfastjson.parser.safeMode=true, calling ParserConfig.getGlobalInstance().setSafeMode(true), or configuring it in fastjson.properties; this blocks @type-based payloads before they reach the vulnerable parsing path.
    • Switch to a noneautotype build such as com.alibaba:fastjson:1.2.83_noneautotype; this removes the vulnerable code path from the deployed artifact.
    • Migrate to fastjson2; this avoids the vulnerable fastjson 1.x parsing behavior in affected deployments.

    How to fix Deserialization of Untrusted Data?

    Upgrade com.alibaba:fastjson to version 1.2.84 or higher.

    [1.2.68,1.2.84)
    • H
    Deserialization of Untrusted Data

    com.alibaba:fastjson is a fast JSON parser/generator for Java.

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers.

    How to fix Deserialization of Untrusted Data?

    Upgrade com.alibaba:fastjson to version 1.2.83 or higher.

    [,1.2.83)