Skip to content

[Bug][Fix-10555] Fastjson has a deserialization vulnerability#10554

Closed
kangyuanjia wants to merge 1 commit intoapache:1.3.9-releasefrom
kangyuanjia:fastjson
Closed

[Bug][Fix-10555] Fastjson has a deserialization vulnerability#10554
kangyuanjia wants to merge 1 commit intoapache:1.3.9-releasefrom
kangyuanjia:fastjson

Conversation

@kangyuanjia
Copy link

@kangyuanjia kangyuanjia commented Jun 22, 2022

Purpose of the pull request

Fix #10555
Fix Fastjson deserialization vulnerability
https://github.com/alibaba/fastjson/wiki/security_update_20220523

Brief change log

./pom.xml

Verify this pull request

This pull request is code cleanup without any test coverage.

Yes

This pull request is already covered by existing tests, such as (please describe tests).

Yes

This change added tests and can be verified as follows:

None

@kangyuanjia kangyuanjia changed the title [Bug] Fastjson has a deserialization vulnerability [Bug][Fix-10555] Fastjson has a deserialization vulnerability Jun 22, 2022
@SbloodyS
Copy link
Member

Hi @kangyuanjia , please submit to dev branch.

@SbloodyS
Copy link
Member

closed due to incorrect target branch.

@SbloodyS SbloodyS closed this Jun 23, 2022
@kangyuanjia
Copy link
Author

kangyuanjia commented Jun 23, 2022

Hi @kangyuanjia , please submit to dev branch.

Hi @SbloodyS ,

There is no fastjson in dev/pom.xml .
Branch 1.3.9-release is the last version which includes fastjson.

@SbloodyS
Copy link
Member

Hi @kangyuanjia , please submit to dev branch.

Hi @SbloodyS ,

There is no fastjson in dev/pom.xml . Branch 1.3.9-release is the last version which includes fastjson.

Then we do not need to care about it since the latest release version does not have this problem

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants