mirror of
https://gitee.com/xiaonuobase/snowy.git
synced 2026-10-06 06:52:58 +08:00
【底座】修复 #IKJ2SR 锁定 fastjson 1.2.84,修复传递依赖 1.2.83 受 CVE-2026-16723 远程代码执行影响的问题
fastjson 1.2.68~1.2.83 在 Spring Boot 可执行 fat-jar 部署下,默认配置(未开启 AutoType、无需 gadget)即可被利用执行任意代码, Snowy 以 java -jar 部署满足触发条件。fastjson 经 JustAuth 1.16.7 与 easy-trans 3.1.4 传递引入,两者最新版仍依赖 1.2.83, 且 JustAuth 公开接口返回 fastjson 的 JSONObject,无法排除,故在根 pom 的 dependencyManagement 中锁定修复版本 1.2.84。 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
committed by
小诺方舟
co-authored by
Claude Opus 5.5
parent
8ff7c08d5b
commit
02b5b42a46
@@ -30,6 +30,7 @@
|
||||
<easy-poi.version>4.4.0</easy-poi.version>
|
||||
<easy-trans.version>3.1.4</easy-trans.version>
|
||||
<easyexcel.version>3.3.3</easyexcel.version>
|
||||
<fastjson.version>1.2.84</fastjson.version>
|
||||
<hutool.version>5.8.25</hutool.version>
|
||||
<ip2region.version>2.7.0</ip2region.version>
|
||||
<java.version>17</java.version>
|
||||
@@ -392,6 +393,13 @@
|
||||
<version>${justauth.version}</version>
|
||||
</dependency>
|
||||
|
||||
<!-- fastjson(JustAuth、easy-trans 传递依赖,锁定 1.2.84 修复 CVE-2026-16723) -->
|
||||
<dependency>
|
||||
<groupId>com.alibaba</groupId>
|
||||
<artifactId>fastjson</artifactId>
|
||||
<version>${fastjson.version}</version>
|
||||
</dependency>
|
||||
|
||||
<!-- opensaml -->
|
||||
<dependency>
|
||||
<groupId>org.opensaml</groupId>
|
||||
|
||||
Reference in New Issue
Block a user