{"id":"CVE-2017-18349","details":"parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.","aliases":["GHSA-xjrr-xv9m-4pw5"],"modified":"2026-07-08T11:35:49.771609Z","published":"2018-10-23T20:29:00.263Z","references":[{"type":"ADVISORY","url":"https://fortiguard.com/encyclopedia/ips/44059"},{"type":"ADVISORY","url":"https://github.com/alibaba/fastjson/wiki/security_update_20170315"},{"type":"EVIDENCE","url":"https://github.com/pippo-java/pippo/issues/466"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/alibaba/fastjson","events":[{"introduced":"0"},{"fixed":"d9bc118f8f91deb696e7265f1d6a4af25880364f"}],"database_specific":{"cpe":"cpe:2.3:a:alibaba:fastjson:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.2.25"}],"source":"CPE_RANGE"}}],"versions":["1.2.14","1.2.13","1.2.8","1.1.33","1.2.7","1.2.24","1.2.23","1.2.22","1.2.21","1.2.20","1.2.19","1.2.18","1.2.17","1.2.16","1.2.15","1.2.12","1.2.11_release","1.2.10","1.2.9","1.2.6","1.2.4","1.2.2","1.2.1","1.2.0","1.1.42","1.1.36","1.1.35","1.1.32","1.1.31","1.1.27","1.1.26","1.1.25","1.1.23","1.1.22","1.1.21","1.1.20"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-18349.json","vanir_signatures_modified":"2026-07-08T11:35:49Z","vanir_signatures":[{"id":"CVE-2017-18349-755bfd69","signature_type":"Function","signature_version":"v1","source":"https://github.com/alibaba/fastjson/commit/d9bc118f8f91deb696e7265f1d6a4af25880364f","target":{"function":"addBaseClassMappings","file":"src/main/java/com/alibaba/fastjson/util/TypeUtils.java"},"deprecated":false,"digest":{"length":2462,"function_hash":"259482791545784874218650089392929453428"}},{"digest":{"line_hashes":["6463697299556542927808781376056503372","201275771541883744973533833935665962205","189240504328428240932588970532724036232","43474646965518383709760935116987632728","187927941506510643786112547406573202282","62227061352496922917485310474228338266","87452775326685901289693920756949413321","294468533860166947624446944572711095371","62388640950824877391530633739139524606","297714496751548969287630883056981386070","331037084458401514036337456020661601810"],"threshold":0.9},"id":"CVE-2017-18349-7b1e779e","signature_type":"Line","signature_version":"v1","source":"https://github.com/alibaba/fastjson/commit/d9bc118f8f91deb696e7265f1d6a4af25880364f","target":{"file":"src/main/java/com/alibaba/fastjson/parser/ParserConfig.java"},"deprecated":false},{"digest":{"line_hashes":["165770401209810732077640163894549307371","128006272351809972047575108058773416101","163691771881932937813037321011886016067","68314709251382234216608956792815974932"],"threshold":0.9},"id":"CVE-2017-18349-8002b077","signature_type":"Line","signature_version":"v1","source":"https://github.com/alibaba/fastjson/commit/d9bc118f8f91deb696e7265f1d6a4af25880364f","target":{"file":"src/test/java/com/alibaba/json/bvt/writeClassName/WriteClassNameTest_Collection.java"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["222461951534141154366471203678530389110","69004162825999077803185095297469866052","69814211049230247572705741608398291800","307268205764531919555922602854819998921","202927005367681576401463143430217171552","239730377404506400106046537531610401116","250850352046871806782391617956292099335","169385827739559897208196565453747764645","167233957634760835519785540254985932723"],"threshold":0.9},"id":"CVE-2017-18349-8dd924d1","signature_type":"Line","signature_version":"v1","source":"https://github.com/alibaba/fastjson/commit/d9bc118f8f91deb696e7265f1d6a4af25880364f","target":{"file":"src/main/java/com/alibaba/fastjson/util/TypeUtils.java"}},{"digest":{"function_hash":"134398788421323971788297794873978615045","length":146},"id":"CVE-2017-18349-e363a974","signature_type":"Function","signature_version":"v1","source":"https://github.com/alibaba/fastjson/commit/d9bc118f8f91deb696e7265f1d6a4af25880364f","target":{"function":"setUp","file":"src/test/java/com/alibaba/json/bvt/writeClassName/WriteClassNameTest_Collection.java"},"deprecated":false}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/pippo-java/pippo","events":[{"introduced":"a2eb20fd813641e343f1a319b5b4b7855b581fec"},{"last_affected":"a2eb20fd813641e343f1a319b5b4b7855b581fec"}],"database_specific":{"cpe":"cpe:2.3:a:pippo:pippo:1.11.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.11.0"},{"last_affected":"1.11.0"}],"source":"CPE_STRING"}}],"versions":["1.11.0","release-1.11.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-18349.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}