Deserialization of Untrusted Datacom.alibaba:fastjson is a fast JSON parser/generator for Java.
Affected versions of this package are vulnerable to Deserialization of Untrusted Data through the JSON parsing path in JSON.parse, JSON.parseObject(String), and JSON.parseObject(String, Class) when it runs inside a Spring Boot executable fat-jar. An attacker can execute code by supplying crafted JSON that reaches the vulnerable type-resolution logic, including nested payloads in Object or Map fields. The issue affects applications using the stock default configuration, and it can let a remote attacker run arbitrary code in the process that deserializes the JSON.
Notes
- The vulnerable path is verified only in Spring Boot executable fat-jar deployments started with
java -jar; plain classpath launches and WAR-style deployments are outside the documented trigger condition.
- The issue is present under fastjson’s stock defaults with
AutoType and SafeMode both off; enabling SafeMode blocks the vulnerable @type handling before this path is reached.
Workarounds
- Enable
SafeMode by setting -Dfastjson.parser.safeMode=true, calling ParserConfig.getGlobalInstance().setSafeMode(true), or configuring it in fastjson.properties; this blocks @type-based payloads before they reach the vulnerable parsing path.
- Switch to a
noneautotype build such as com.alibaba:fastjson:1.2.83_noneautotype; this removes the vulnerable code path from the deployed artifact.
- Migrate to
fastjson2; this avoids the vulnerable fastjson 1.x parsing behavior in affected deployments.
How to fix Deserialization of Untrusted Data? Upgrade com.alibaba:fastjson to version 1.2.84 or higher.
| |