The JSON deserialization functionality in Fastjson 1.2.68 through 1.2.83 and Fastjson2 <= 2.0.62 contains a class loading vulnerability. When the affected software parses attacker-controllable JSON data, an @type value crafted using a JAR file or HTTP address may cause Fastjson to parse and load classes, thereby leading to remote code execution or server-side request forgery. Other reference:None