alibaba / alibaba/DataX

反序列化漏洞

Open
#2,169 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
17.4k
Forks
5.7k
PR merge metrics
No merged PRs in 30d

Description

Apache Commons Collections <= 3.2.1 反序列化漏洞

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue only reports an Apache Commons Collections deserialization vulnerability affecting versions up to 3.2.1 and names no files or tests. First locate where this dependency is declared in DataX and check how dependencies are verified; done means the vulnerable version is no longer used and the relevant build or security check passes.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.