Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-24163 不处理下吗? #3149

Closed
coderstory opened this issue Jun 14, 2023 · 5 comments
Closed

CVE-2023-24163 不处理下吗? #3149

coderstory opened this issue Jun 14, 2023 · 5 comments
Labels

Comments

@coderstory
Copy link

参考 murphysecurity/murphysec-jetbrains-plugin#15

@looly
Copy link
Member

looly commented Jun 14, 2023

原文已经说了,Hutool只是表达式门面的封装,实际漏洞来自于aviator或任意第三方的表达式库。

作为门面无法做到修复。

@looly looly closed this as completed Jun 14, 2023
@looly looly added the question label Jun 14, 2023
@looly
Copy link
Member

looly commented Jun 14, 2023

PS:

6.0.0已经将整个ExpressUtil移除。

@reixuemin
Copy link

PS:

6.0.0已经将整个ExpressUtil移除。

那是有其它的替代,还是说表达式计算ExpressionUtil以后都不支持了?

@looly
Copy link
Member

looly commented Jun 30, 2023

@reixuemin 表达式计算很多实现库根本没有对注入的防护,因此删除后没有替代。

如果需要,考虑至今引用原生表达式库使用。

@looly
Copy link
Member

looly commented Aug 11, 2023

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants