Deserialization of Untrusted Data Affecting ro.pippo:pippo-core package, versions [0.9,1.12.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.22% (86th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Deserialization of Untrusted Data vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ROPIPPO-174587
  • published6 Nov 2018
  • disclosed30 Sept 2018
  • creditidealzh

Introduced: 30 Sep 2018

CVE-2018-18240  (opens in a new tab)
CVE-2018-18628  (opens in a new tab)
CWE-352  (opens in a new tab)

How to fix?

Upgrade ro.pippo:pippo-core to version 1.12.0 or higher.

Overview

ro.pippo:pippo-core is a Micro Java Web Framework.

Affected versions of this package are vulnerable to Deserialization of Untrusted Data. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the object types.

CVSS Scores

version 3.1