Skip to content

GitLab

  • Menu
Projects Groups Snippets
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • M mall
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 0
    • Issues 0
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 5
    • Merge requests 5
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Packages & Registries
    • Packages & Registries
    • Package Registry
    • Infrastructure Registry
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • maxiaotian
  • mall
  • Merge requests
  • !2

Open
Created Jun 16, 2023 by liangjiawei@liangjiawei
  • Report abuse
Report abuse

请升级com.fasterxml.jackson.core:jackson-databind组件版本以解决54个安全漏洞

  • Overview 0
  • Commits 1
  • Changes 1

将 net.logstash.logback:logstash-logback-encoder 组件从5.3 版本升级至 6.0版本, org.springframework.data:spring-data-commons 组件从2.3.0.RELEASE 版本升级至 2.3.1.RELEASE版本, com.alibaba:druid-spring-boot-starter 组件从1.1.23 版本升级至 1.2.9版本, com.github.pagehelper:pagehelper-spring-boot-starter 组件从1.3.0 版本升级至 1.3.1版本, io.springfox:springfox-swagger2 组件从2.9.2 版本升级至 3.0.0版本, com.github.pagehelper:pagehelper 组件从5.2.0 版本升级至 5.3.1版本, io.springfox:springfox-swagger-ui 组件从2.9.2 版本升级至 2.10.0版本, 用于修复以下安全漏洞:

序号 漏洞编号 漏洞标题 漏洞级别
1 MPS-2020-17696 FasterXML jackson-databind 反序列化漏洞(commons-dbcp2 gadget绕过) 高危
2 MPS-2020-8911 FasterXML jackson-databind代码问题漏洞(jsecurity gadget绕过) 高危
3 MPS-2021-0212 FasterXML jackson-databind 反序列化漏洞(newrelic-agent gadget绕过) 高危
4 MPS-2021-0211 FasterXML jackson-databind 反序列化漏洞(newrelic-agent gadget绕过) 高危
5 MPS-2021-0204 FasterXML jackson-databind 反序列化漏洞(DBCP gadget绕过) 高危
6 MPS-2021-0205 FasterXML jackson-databind 反序列化漏洞(tomcat-dbcp gadget绕过) 高危
7 MPS-2022-6242 FasterXML jackson-databind 拒绝服务漏洞 高危
8 MPS-2019-7047 FasterXML jackson-databind 反序列化漏洞(logback-classic gadget绕过) 中危
9 MPS-2020-3094 FasterXML Jackson-databind反序列化漏洞(xalan2 gadget绕过) 严重
10 MPS-2019-11533 FasterXML jackson-databind 反序列化漏洞(HikariCP gadget绕过) 严重
11 MPS-2019-12479 FasterXML jackson-databind 反序列化漏洞(commons-dbcp gadget绕过) 严重
12 MPS-2019-12480 FasterXML jackson-databind 反序列化漏洞(p6spy gadget绕过) 严重
13 MPS-2019-12676 FasterXML jackson-databind 反序列化漏洞(ehcache gadget绕过) 严重
14 MPS-2020-4132 FasterXML jackson-databind反序列化漏洞(caucho-quercus gadget绕过) 高危
15 MPS-2020-4658 FasterXML jackson-databind反序列化漏洞(bus-proxy gadget绕过) 高危
16 MPS-2020-4754 FasterXML jackson-databind反序列化漏洞(activemq gadget绕过) 高危
17 MPS-2020-4755 FasterXML jackson-databind反序列化漏洞(commons-proxy gadget绕过) 高危
18 MPS-2020-5138 FasterXML jackson-databind 反序列化漏洞(spring-aop gadget绕过) 高危
19 MPS-2020-8803 FasterXML jackson-databind反序列化漏洞(apache drill gadget绕过) 高危
20 MPS-2020-11987 FasterXML jackson-databind反序列化漏洞(Anteros-DBCP gadget绕过) 高危
21 MPS-2020-13151 FasterXML jackson-databind 反序列化漏洞(pastdev gadget绕过) 高危
22 MPS-2020-17697 FasterXML jackson-databind 反序列化漏洞(commons-dbcp2 gadget绕过) 高危
23 MPS-2021-0208 FasterXML jackson-databind 反序列化漏洞(tomcat-dbcp gadget绕过) 高危
24 MPS-2020-3042 FasterXML jackson-databind反序列化漏洞(anteros-core gadget绕过) 严重
25 MPS-2022-12433 com.fasterxml.jackson.core:jackson-databind 存在反序列化漏洞 高危
26 MPS-2020-3075 FasterXML jackson-databind 反序列化漏洞(commons-configuration gadget绕过) 严重
27 MPS-2021-0206 FasterXML jackson-databind 反序列化漏洞(docx4j gadget绕过) 高危
28 MPS-2021-0209 FasterXML jackson-databind 反序列化漏洞(naming-factory-dbcp gadget绕过) 高危
29 MPS-2021-0210 FasterXML jackson-databind 反序列化漏洞(naming-factory-dbcp gadget绕过) 高危
30 MPS-2022-58654 FasterXML jackson-databind 小于2.13.4拒绝服务漏洞 中危
31 MPS-2019-5442 FasterXML jackson-databind 反序列化漏洞(mysql gadget绕过) 高危
32 MPS-2019-8770 FasterXML jackson-databind 信息泄露漏洞(logback gadget绕过) 高危
33 MPS-2020-24779 FasterXML jackson-databind 反序列化漏洞(ignite-jta gadget绕过) 高危
34 MPS-2020-4131 FasterXML jackson-databind反序列化漏洞(aries.transaction.jms gadget绕过) 高危
35 MPS-2020-8801 FasterXML jackson-databind反序列化漏洞(oracle-aqjms gadget绕过) 高危
36 MPS-2020-8802 FasterXML jackson-databind反序列化漏洞(xalan2 gadget绕过) 高危
37 MPS-2020-18089 FasterXML jackson-databind 反序列化漏洞(glassfish gadget绕过) 高危
38 MPS-2021-0202 FasterXML jackson-databind 反序列化漏洞(DBCP gadget绕过) 高危
39 MPS-2021-1625 FasterXML jackson-databind 反序列化漏洞(javax.swing gadget绕过) 高危
40 MPS-2020-3041 FasterXML jackson-databind 反序列化漏洞(JtaTransactionConfig gadget绕过) 严重
41 MPS-2020-17358 FasterXML jackson-databind 代码问题漏洞 高危
42 MPS-2019-11529 FasterXML jackson-databind 反序列化漏洞(HikariCP gadget绕过) 严重
43 MPS-2020-2030 FasterXML jackson-databind 反序列化漏洞(xbean-reflect gadget绕过) 严重
44 MPS-2019-13103 FasterXML jackson-databind 反序列化漏洞(apache-log4j-extras gadget绕过) 严重
45 MPS-2020-4659 FasterXML jackson-databind反序列化漏洞(javax.swing gadget绕过) 高危
46 MPS-2019-6867 FasterXML jackson-databind 反序列化漏洞(jdom gadget绕过) 中危
47 MPS-2020-4756 FasterXML jackson-databind反序列化漏洞(openjpa gadget绕过) 高危
48 MPS-2021-0203 FasterXML jackson-databind 反序列化漏洞(DBCP gadget绕过) 高危
49 MPS-2021-0207 FasterXML jackson-databind 反序列化漏洞(tomcat-dbcp gadget绕过) 高危
50 MPS-2022-58653 FasterXML jackson-databind 小于2.14.0-rc1拒绝服务漏洞 中危
51 MPS-2020-3040 FasterXML jackson-databind 代码问题漏洞 严重
52 MPS-2020-0063 FasterXML jackson-databind反序列化漏洞(net.sf.ehcache gadget绕过) 严重
53 MPS-2020-5139 FasterXML jackson-databind 反序列化漏洞(commons-jelly gadget绕过) 高危
54 MPS-2019-8717 FasterXML jackson-databind 反序列化漏洞(ehcache gadget绕过) 严重
        

注意 :此 PR 由您(或拥有此仓库权限的其他维护者)授权 墨菲安全 打开

了解更多:

  • 如何快速修复代码安全问题
Assignee
Assign to
Reviewer
Request review from
Time tracking
Source branch: fix_ci5vv26glomnof74kat0