IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
http://breeze.github.io/doc-net/release-notes.html | release notes vendor advisory |
https://www.blackhat.com/us-17/briefings.html#friday-the-13th-json-attacks | technical description |