Pippo

Pippo

5 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.33%
  • Published 12.06.2019 16:29:00
  • Last modified 21.11.2024 04:44:56

XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large amounts of heap memory is taken. Eventually, the JVM process will run out of memory. Otherwise, if the OS does not bo...

Exploit
  • EPSS 0.4%
  • Published 11.12.2018 10:29:00
  • Last modified 21.11.2024 04:00:49

jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.

Exploit
  • EPSS 90.63%
  • Published 23.10.2018 20:29:00
  • Last modified 21.11.2024 03:19:54

parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of ...

Exploit
  • EPSS 4.39%
  • Published 23.10.2018 20:29:00
  • Last modified 21.11.2024 03:56:15

An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the object types. An attacker can create a malicious object, b...

Exploit
  • EPSS 2.71%
  • Published 11.10.2018 07:29:00
  • Last modified 21.11.2024 03:55:34

Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict unmarshalling.