Fasterxml | Jackson ¶à¸ö·´ÐòÁл¯·ì϶
°ä²¼¹¦·ò 2020-08-270x00 ·ì϶¸ÅÊö
±àºÅ | issue:2798¡¢issue:2814¡¢issue:2826¡¢issue:2827 | ʱ¼ä | 2020-08-27 |
ÀàÐÍ | µÈ¼¶ | ¸ßΣ | |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | jackson-databind < 2.9.10.6 |
FasterxmlÖØÒªÓÃÓÚJava ƽ̨µÄÊý¾Ý·ÖÎö¡£¡£¡£¡£¡£¡£¡£jackson-databindÊÇFasterXMLÏîÑÛǰµÄJSON¿â¡£¡£¡£¡£¡£¡£¡£
Fasterxml jackson-databind 2.9.10.6֮ǰµÄ°æ±¾ÖдæÔÚ¶à¸ö·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¾«ÐÄ»ú¹ØµÄpayloadÔÚϵͳÉÏÖ´ÐжñÒâ´úÂ룬£¬£¬£¬£¬£¬JacksonÊÇSpringBootÖÐÊ×Ñ¡ºÍĬÈϵÄת»»¹¤¾ß¡£¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

issue:2798
¸ÃÎÊÌâÊÇÓÉÓÚcom.pastdev.httpcomponents:configuration ×é¼þ¿â´æÔÚ²»°²È«µÄ·´ÐòÁл¯¡£¡£¡£¡£¡£¡£¡£
issue:2814
¸ÃÎÊÌâÊÇÓÉÓÚbr.com.anteros:Anteros-DBCP ×é¼þ¿â´æÔÚ²»°²È«µÄ·´ÐòÁл¯£¬£¬£¬£¬£¬£¬ÒÑ·ÖÅäCVE±àºÅ£ºCVE-2020-24616¡£¡£¡£¡£¡£¡£¡£
issue:2826
¸ÃÎÊÌâÊÇÓÉÓÚcom.nqadmin.rowset:jdbcrowsetimpl ×é¼þ¿â´æÔÚ²»°²È«µÄ·´ÐòÁл¯¡£¡£¡£¡£¡£¡£¡£
issue:2827
¸ÃÎÊÌâÊÇÓÉÓÚorg.arrahtec:profiler-core ×é¼þ¿â´æÔÚ²»°²È«µÄ·´ÐòÁл¯¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
Éý¼¶µ½×îеİ汾£¬£¬£¬£¬£¬£¬ÈçÁÙʱÎÞ·¨Éý¼¶£¬£¬£¬£¬£¬£¬½¨Òé²»ÈÝ»¥ÁªÍø½Ó¼û·´ÐòÁл¯½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£
0x03 ÓйØÐÂÎÅ
0x04 ²Î¿¼Á´½Ó
https://github.com/Fasterxml/jackson-databind/issues/2798
https://github.com/FasterXML/jackson-databind/issues/2814
https://github.com/Fasterxml/jackson-databind/issues/2826
https://github.com/Fasterxml/jackson-databind/issues/2827
0x05 ¹¦·òÏß
2020-08-27 VSRC°ä²¼·ì϶¹«¸æ



¾©¹«Íø°²±¸11010802024551ºÅ