Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

请问jeecgboot2.4.6也存在此漏洞吗?请问如何测试已修正完毕呢? #5346

Closed
lntlky7 opened this issue Sep 5, 2023 · 1 comment

Comments

@lntlky7
Copy link

lntlky7 commented Sep 5, 2023

版本号:2.4.6
前端版本:vue2
问题描述:

---重构表字典逻辑,深度解决SQL注入漏洞问题,新旧版本都可以参考此修改合并---

9月5日发布的jeecgboot的漏洞问题,重构表字典逻辑,请问这个漏洞影响到哪个接口,如何验证已修复完毕。
我们用的jeecgboot2.4.6版本,也存在这个漏洞吗?请问如何验证?
重构表字典逻辑的代码我看了一下,有些类在2.4.6中不存在,请问是不是只处理存在的类就可以了?
期望答复,谢谢。

截图&代码:

友情提示(为了提高issue处理效率):

  • 未按格式要求发帖,会被直接删掉;
  • 描述过于简单或模糊,导致无法处理的,会被直接删掉;
  • 请自己初判问题描述是否清楚,是否方便我们调查处理;
  • 针对问题请说明是Online在线功能(需说明用的主题模板),还是生成的代码功能;
@zhangdaiscott
Copy link
Member

zhangdaiscott commented Sep 5, 2023

老版本都存在

用这三个进行验证
#5134
#4737
#5173

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants