10

CVE-2025-70974

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection with an attacker-supplied payload located elsewhere in that JSON document. This was exploited in the wild in 2023 through 2025. NOTE: this issue exists because of an incomplete fix for CVE-2017-18349. Also, a later bypass is covered by CVE-2022-25845.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
HerstellerRed Hat
Produkt OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
Produkt OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
Produkt OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
Produkt OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
Produkt OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
Produkt OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
Produkt OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
Produkt OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat build of Apache Camel for Spring Boot 4
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat build of Debezium 2
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat build of Debezium 3
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat Fuse 7
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform 8
Default Statusunaffected
HerstellerRed Hat
Produkt Red Hat JBoss Enterprise Application Platform Expansion Pack
Default Statusunaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.7% 0.498
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
MITRE 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-829 Inclusion of Functionality from Untrusted Control Sphere

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

https://github.com/alibaba/fastjson/compare/1.2.47...1.2.48
https://www.seebug.org/vuldb/ssvid-98020
https://www.freebuf.com/vuls/208339.html
https://github.com/vulhub/vulhub/tree/master/fastjson/1.2.47-rce
https://www.cloudsek.com/blog/androxgh0st-continues-exploitation-operators-compromise-a-us-university-for-hosting-c2-logger
https://cert.360.cn/warning/detail?id=7240aeab581c6dc2c9c5350756079955
https://bugzilla.redhat.com/show_bug.cgi?id=2428203
https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-70974.json
https://www.cnvd.org.cn/flaw/show/CNVD-2019-22238
https://access.redhat.com/security/cve/CVE-2025-70974