Update fastjson-1-2-68-rce.yaml

patch-1
Prince Chaddha 2022-05-31 14:12:39 +05:30 committed by GitHub
parent 4c90184054
commit 3106c22125
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 1 deletions

View File

@ -4,7 +4,8 @@ info:
name: Fastjson 1.2.68 - Remote Code Execution name: Fastjson 1.2.68 - Remote Code Execution
author: zh author: zh
severity: critical severity: critical
description: Fastjson 1.2.68 is susceptible to a deserialization remote code execution vulnerability. description: |
Fastjson 1.2.68 is susceptible to a deserialization remote code execution vulnerability.
reference: reference:
- https://github.com/tdtc7/qps/tree/4042cf76a969ccded5b30f0669f67c9e58d1cfd2/Fastjson - https://github.com/tdtc7/qps/tree/4042cf76a969ccded5b30f0669f67c9e58d1cfd2/Fastjson
- https://github.com/wyzxxz/fastjson_rce_tool - https://github.com/wyzxxz/fastjson_rce_tool