Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict unmarshalling.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ro.pippo:pippo-core(Maven) | 0 | 1.12.0 | N/A |
| ro.pippo:pippo-session(Maven) | 0 | 1.12.0 | N/A |
CVSS Metrics