CVE-2017-18349
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a...
- Published
- Oct 23, 2018
- Updated
- Sep 17, 2024
- Assigning CNA
- mitre
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:CModerate · next 30 days
- Percentile
- 97.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.
Sources
2Step-by-step walkthrough of CVE-2017-18349 Fastjson deserialization RCE exploitation, covering attack surface identification, fingerprinting, JNDI injection, and reverse shell acquisition in a Docker lab environment.
Proof-of-concept exploit for Fastjson CVE-2017-18349 deserialization vulnerability, demonstrating remote code execution via crafted JSON payload and RMI server.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.