CVE-2018-18240: Critical severity Pippo Pippo vulnerability
Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict unmarshalling.
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2018-18240.
What is the severity of CVE-2018-18240?
The severity of CVE-2018-18240 is critical with a score of 9.8.
How does Pippo through 1.11.0 allow remote code execution?
Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict unmarshalling.
Which software is affected by CVE-2018-18240?
The following software packages are affected by CVE-2018-18240: ro.pippo:pippo-parent 1.11.0, ro.pippo:pippo-session 1.11.0, ro.pippo:pippo-core 1.11.0, Pippo Pippo 1.11.0.
How can I fix CVE-2018-18240?
To fix CVE-2018-18240, update the affected software packages to version 1.12.0 or later.