Recently, a remote code execution vulnerability has been disclosed in Fastjson2. Under the default configuration where SupportAutoType is disabled, the AutoType allowlist validation relies solely on hash matching rather than verifying the actual class name. This flaw allows attackers to bypass security controls and trigger arbitrary remote class loading.
Fastjson2 is a high-performance, next-generation JSON library for Java, developed by Alibaba. It provides efficient serialization and deserialization between Java objects and JSON strings. If you are a Fastjson2 user, check your system and implement timely security hardening.
Reference:
important
(Severity: low, medium, important, and critical)
Fastjson 2.x <= 2.0.62
Fastjson 2.x >= 2.0.63
This vulnerability has been fixed in later official versions. If your service version falls into the affected range, upgrade it to a latest secure version.
https://github.com/alibaba/fastjson2/releases/
Note: Before fixing vulnerabilities, back up your files and conduct a thorough test.
Get more professional support at any time
Contact Us