FasterXML jackson-databindÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-31

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-14361£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-14379£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


²úÆ·


FastXML


°æ±¾


FasterXMLjackson-databind<2.9.9.2
FasterXMLjackson-databind<2.10.0
FasterXMLjackson-databind<2.7.9.6

FasterXMLjackson-databind<2.8.11.4


×é¼þ


FasterXMLjackson-databind

FasterXMLback-ported


Îó²î¸ÅÊö


FasterXMLjackson-databindÊÇÒ»¸ö¼òÆÓ»ùÓÚJavaÓ¦Óÿ⣬£¬£¬Jackson¿ÉÒÔÇáËɵĽ«Java¹¤¾ßת»»³Éjson¹¤¾ßºÍxmlÎĵµ£¬£¬£¬Í¬ÑùÒ²¿ÉÒÔ½«json¡¢xmlת»»³ÉJava¹¤¾ß¡£¡£¡£¡£¡£


FasterXMLjackson-databind±£´æ·´ÐòÁл¯Îó²î²¹¶¡Èƹý¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÎó²îÖ´ÐдúÂë¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


EXP: https://github.com/Heartway


ÐÞ¸´½¨Òé


1¡¢Éý¼¶FasterXMLjackson-databind°æ±¾µ½2.9.9.2,2.10.0,2.7.9.6,2.8.11.4
2¡¢²»¿ªÆôJacksonµÄdefaultTypingÑ¡Ïî

²Î¿¼Á´½Ó


https://github.com/FasterXML/jackson-databind/issues/2387 
https://github.com/FasterXML/jackson-databind/issues/2389