Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Two security holes: jackson-databind and fastjson. Associated version edp963/davinci: v0.3.0-beta.9 #1783

Open
silegon opened this issue Jun 2, 2020 · 0 comments
Assignees

Comments

@silegon
Copy link

silegon commented Jun 2, 2020

修复建议
针对使用到jackson-databind组件的web服务器升级jackson相关组件至最新版本:FasterXML/jackson-databind#2334
注意:
Jackson漏洞检测规则是通过判定机器运行时的jar包中是否存在漏洞版本的jackson-databind组件,无法精准确认漏洞有效攻击面,实际是否真实受漏洞影响还需用户根据自身业务判断
Inkedjackson_bug_LI

修复建议
较低版本升级至最新版本1.2.60可能会出现兼容性问题,建议升级至特定版本的sec06 bugfix版本,参考下载链接:http://repo1.maven.org/maven2/com/alibaba/fastjson/
注意:
fastjson漏洞检测规则是通过判定机器运行时的jar包中是否存在漏洞版本的fastjson组件,无法精准确认漏洞有效攻击面,仅供参考,不具备真实受漏洞影响判定,实际是否真实受漏洞影响还需用户根据自身业务判断。
Inkedfastjson_bug_LI

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants