FasterXML jackson-databindÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-07-31? Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-14379£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
? Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
²úÆ·
FastXML
°æ±¾
FasterXMLjackson-databind<2.10.0
FasterXMLjackson-databind<2.7.9.6
FasterXMLjackson-databind<2.8.11.4
×é¼þ
FasterXMLback-ported
? Îó²î¸ÅÊö
FasterXMLjackson-databindÊÇÒ»¸ö¼òÆÓ»ùÓÚJavaÓ¦Óÿ⣬£¬£¬£¬£¬£¬£¬Jackson¿ÉÒÔÇáËɵĽ«Java¹¤¾ßת»»³Éjson¹¤¾ßºÍxmlÎĵµ£¬£¬£¬£¬£¬£¬£¬Í¬ÑùÒ²¿ÉÒÔ½«json¡¢xmlת»»³ÉJava¹¤¾ß¡£¡£¡£
FasterXMLjackson-databind±£´æ·´ÐòÁл¯Îó²î²¹¶¡Èƹý¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÎó²îÖ´ÐдúÂë¡£¡£¡£
? Îó²îÑéÖ¤
EXP: https://github.com/Heartway
? ÐÞ¸´½¨Òé
2¡¢²»¿ªÆôJacksonµÄdefaultTypingÑ¡Ïî
? ²Î¿¼Á´½Ó
https://github.com/FasterXML/jackson-databind/issues/2389


¾©¹«Íø°²±¸11010802024551ºÅ