Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

请升级com.alibaba:fastjson组件版本以解决6个安全漏洞#4

Open
lijiaqigithub wants to merge 1 commit intomasterlijiaqigithub/java:masterfrom
oscs_fix_cp68jsfbl82jl6mfe7h0lijiaqigithub/java:oscs_fix_cp68jsfbl82jl6mfe7h0Copy head branch name to clipboard
Open

请升级com.alibaba:fastjson组件版本以解决6个安全漏洞#4
lijiaqigithub wants to merge 1 commit intomasterlijiaqigithub/java:masterfrom
oscs_fix_cp68jsfbl82jl6mfe7h0lijiaqigithub/java:oscs_fix_cp68jsfbl82jl6mfe7h0Copy head branch name to clipboard

Conversation

@lijiaqigithub
Copy link
Owner

com.alibaba:fastjson 组件从1.2.9 版本升级至 2.0.18版本,
用于修复以下安全漏洞:

序号 漏洞编号 漏洞标题 漏洞级别
1 MPS-2019-28847 Fastjson <= 1.2.60 版本远程代码执行漏洞 严重
2 MPS-2019-28848 Fastjson < 1.2.60 版本拒绝服务漏洞 严重
3 MPS-2020-39708 Fastjson <=1.2.68 远程代码执行漏洞 严重
4 MPS-2018-14062 Fastjson < 1.2.25版本远程代码执行漏洞 严重
5 MPS-2022-11320 Fastjson < 1.2.83 任意代码执行漏洞 高危
6 MPS-2020-40828 Fastjson < 1.2.67远程命令执行漏洞 高危
        

注意 :此 PR 由您(或拥有此仓库权限的其他维护者)授权 墨菲安全 打开

了解更多:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Morty Proxy This is a proxified and sanitized view of the page, visit original site.