Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fastjson deserialization arbitrary code execution security vulnerability #106

Closed
tianliuliu opened this issue May 26, 2022 · 0 comments · Fixed by #107
Closed

fastjson deserialization arbitrary code execution security vulnerability #106

tianliuliu opened this issue May 26, 2022 · 0 comments · Fixed by #107

Comments

@tianliuliu
Copy link
Contributor

image

when fastjson <= 1.2.80 , there are fastjson deserialization arbitrary code execution security vulnerability,

https://www.oscs1024.com/hd/MPS-2022-11320

tianliuliu added a commit to tianliuliu/rocketmq-mqtt that referenced this issue May 26, 2022
tianliuliu added a commit that referenced this issue May 26, 2022
[ISSUE #106] fix fastjson update version to 1.2.83
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant