Fastjson 安全漏洞
Open
- Dominant language
- Java
- Stars
- 17.4k
- Forks
- 5.7k
- PR merge metrics
- No merged PRs in 30d
Description
当前所有版本都没有对fastjson进行升级,当时当前版本1.1.46.sec10存在已知的安全漏洞:https://github.com/alibaba/fastjson/wiki/update_faq_20190722
有升级的计划吗?或者如果自行升级到安全版本会有什么影响吗?
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reading the linked fastjson security advisory and checking where DataX declares or packages fastjson 1.1.46.sec10. Determine a supported secure version and document compatibility risks; the issue is complete when the vulnerable dependency is addressed and the impact of the upgrade is verified.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100