You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@rocketmq.apache.org by GitBox <gi...@apache.org> on 2022/01/04 10:12:28 UTC

[GitHub] [rocketmq-dashboard] jacksonlingda opened a new issue #60: 这个项目引用了com.fasterxml.jackson.core:jackson-databind@2.10.1组件,存在一个严重漏洞,建议升级

jacksonlingda opened a new issue #60:
URL: https://github.com/apache/rocketmq-dashboard/issues/60


   大佬,我看你这个项目引用了com.fasterxml.jackson.core:jackson-databind@2.10.1组件,存在一个严重漏洞,建议你升级下。
   ```
   漏洞标题:FasterXML jackson-databind 代码问题漏洞
   漏洞描述:
   FasterXML jackson-databind是一个基于JAVA可以将XML和JSON等数据格式与JAVA对象进行转换的库。Jackson可以轻松的将Java对象转换成json对象和xml文档,同样也可以将json、xml转换成Java对象。
   FasterXML Jackson Databind存在代码问题漏洞,攻击者可利用该漏洞可以将恶意的XML数据传输到FasterXML Jackson Databind,以读取文件、扫描站点或触发拒绝服务。
   漏洞级别:高危
   影响范围:[2.10.0, 2.10.5.1)
   最小修复版本:2.10.5.1
   引入路径:
   org.apache.rocketmq:rocketmq-dashboard:1.0.1-SNAPSHOT->org.springframework.boot:spring-boot-starter-web@2.2.2.RELEASE->org.springframework.boot:spring-boot-starter-json@2.2.2.RELEASE->com.fasterxml.jackson.core:jackson-databind@2.10.1
   ```
   除此之外还有4个严重的漏洞,您也可以一键接入墨菲安全的代码安全检测工具,持续监测您的项目:https://www.murphysec.com/j?p=b3dccb


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscribe@rocketmq.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [rocketmq-dashboard] zhangjidi2016 commented on issue #60: 这个项目引用了com.fasterxml.jackson.core:jackson-databind@2.10.1组件,存在一个严重漏洞,建议升级

Posted by GitBox <gi...@apache.org>.
zhangjidi2016 commented on issue #60:
URL: https://github.com/apache/rocketmq-dashboard/issues/60#issuecomment-1004958091


   Thank you for your advice. We will update the version of SpringBoot later to avoid this vulnerability.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscribe@rocketmq.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [rocketmq-dashboard] vongosling closed issue #60: 这个项目引用了com.fasterxml.jackson.core:jackson-databind@2.10.1组件,存在一个严重漏洞,建议升级

Posted by GitBox <gi...@apache.org>.
vongosling closed issue #60:
URL: https://github.com/apache/rocketmq-dashboard/issues/60


   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscribe@rocketmq.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org