IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.
References
Link | Resource |
---|---|
https://www.blackhat.com/us-17/briefings.html#friday-the-13th-json-attacks | Technical Description |
http://breeze.github.io/doc-net/release-notes.html | Release Notes Vendor Advisory |
Configurations
Information
Published : 2017-06-22 09:29
Updated : 2017-06-30 09:12
NVD link : CVE-2017-9424
Mitre link : CVE-2017-9424
JSON object : View
CWE
CWE-502
Deserialization of Untrusted Data
Products Affected
ideablade
- breeze.server.net