10
CVE-2025-70974
- EPSS 0.7%
- Veröffentlicht 09.01.2026 06:43:23
- Zuletzt bearbeitet 15.07.2026 02:17:53
- CVE-Watchlists
- Unerledigt
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection with an attacker-supplied payload located elsewhere in that JSON document. This was exploited in the wild in 2023 through 2025. NOTE: this issue exists because of an incomplete fix for CVE-2017-18349. Also, a later bypass is covered by CVE-2022-25845.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
HerstellerRed Hat
≫
Produkt
OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
OpenShift Service Mesh 2
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Apache Camel for Spring Boot 4
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Debezium 2
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Debezium 3
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat Fuse 7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat JBoss Enterprise Application Platform 8
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat JBoss Enterprise Application Platform Expansion Pack
Default Statusunaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.7% | 0.498 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
| 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-829 Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
https://github.com/alibaba/fastjson/compare/1.2.47...1.2.48
https://www.seebug.org/vuldb/ssvid-98020
https://www.freebuf.com/vuls/208339.html
https://github.com/vulhub/vulhub/tree/master/fastjson/1.2.47-rce
https://www.cloudsek.com/blog/androxgh0st-continues-exploitation-operators-compromise-a-us-university-for-hosting-c2-logger
https://cert.360.cn/warning/detail?id=7240aeab581c6dc2c9c5350756079955
https://bugzilla.redhat.com/show_bug.cgi?id=2428203
https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-70974.json
https://www.cnvd.org.cn/flaw/show/CNVD-2019-22238
https://access.redhat.com/security/cve/CVE-2025-70974