- You can enable safemode by setting `safeJsonType to false and safeJsonPadding to `. - Another way to avoid this issue is to deserialize json data using `. - You can use a data type that is not vulnerable to this issue. For example, `. - You can disable auto type and choose your own data type. - Be cautious when you receive large amount of json data. - Check your server certificate. - Check your server configuration. - This issue can be mitigated by upgrading to fastjson 1.2.83 or later. - Another way to avoid this issue is to deserialize json data using `. - You can use a data type that is not vulnerable to this issue. For example, `. - You can disable auto type and choose your own data type. - Be cautious when you receive large amount of json data. - Check your server certificate. - Check your server configuration. - This issue can be mitigated by upgrading to fastjson 1.2.83 or later. - Another way to avoid this issue is to deserialize json data using `. - You can disable auto type and choose your own data type. - Be cautious when you receive large amount of json data. - Check your server certificate. - Check your server configuration. - This issue can be mitigated by upgrading to fastjson 1.2.83 or later. - Another way to avoid this issue is to deserialize json

JSON Object Type Confusion

This vulnerability can be mitigated by upgrading to fastjson 1.2.83 or later.
The vulnerability can be avoided by deserializing the object using `.
- You can enable safemode by setting `safeJsonType to false and safeJsonPadding to `
- Another way to avoid this issue is to deserialize json data using `
- You can use a data type that is not vulnerable to this issue. For example, `
- You can disable auto type and choose your own data type.
- Be cautious when you receive large amount of json data. - Check your server certificate. - Check your server configuration. - This issue can be mitigated by upgrading to fastjson 1.2.83 or later
- Another way to avoid this issue is to deserialize json data using `
- You can disable auto type and choose your own data type

Timeline

Published on: 06/10/2022 20:15:00 UTC
Last modified on: 07/25/2022 18:22:00 UTC

References