alibaba / alibaba/Sentinel

FasterXML jackson-databind 代码问题漏洞(CVE-2022-42003)

Open
#2,950 7 comments 0 reactions 0 assignees View on GitHub
dependencies good first issue
Dominant language
Java
Stars
23.1k
Forks
8.1k
PR merge metrics
No merged PRs in 30d

Description

最新sentinel-dashboard1.8.6
中jackson-databind 版本是jackson-databind-2.12.6.1.jar

有处理此漏洞的计划吗?

CVE编号
CVE-2022-42003
披露时间
2022-10-02

修复方案
建议受影响客户升级到2.14.0-rc2及以上安全版本,版本获取链接:
https://github.com/FasterXML/jackson-databind

Contributor guide

Open the contributing guide

Research direction

The issue names Sentinel Dashboard 1.8.6, jackson-databind-2.12.6.1.jar, CVE-2022-42003, and the FasterXML advisory link. First locate where that dependency version is declared and check upgrade compatibility; done means the affected version is no longer used and the vulnerability is addressed.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.