A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 07 May 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alldata
Alldata alldata |
|
| CPEs | cpe:2.3:a:alldata:alldata:0.4.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Alldata
Alldata alldata |
Wed, 04 Sep 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-04-01T00:00:00
Updated: 2024-09-04T15:57:51.349Z
Reserved: 2024-03-19T00:00:00
Link: CVE-2024-29433
Updated: 2024-08-02T01:10:55.425Z
Status : Analyzed
Published: 2024-04-01T20:15:14.117
Modified: 2025-05-07T00:36:03.690
Link: CVE-2024-29433
No data.