Pippo RCE Vulnerability
Critical severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Oct 6, 2023
Description
Published by the National Vulnerability Database
Oct 11, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 20, 2023
Last updated
Oct 6, 2023
Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict unmarshalling.
References