è¦ç¹ã ãã¾ã¨ããèªã¿ããããããµããªè¨äºãå ¬éãã¾ãããã¾ãæ¦è¦ãç¥ãããæ¹ããããã¯ãæéã«ä½è£ã®ç¡ãæ¹ã«ããããã§ãã SSTtechlog 08 S2-054, S2-055 ããã³ jackson-databindã®èå¼±æ§ CVE-2017-7525, CVE-2017-15095 ã«ã¤ã㦠| SST æ ªå¼ä¼ç¤¾ã»ãã¥ã¢ã¹ã«ã¤ã»ãã¯ããã¸ã¼ https://www.securesky-tech.com/column/techlog/08.html 2017å¹´12æ1æ¥ã«Struts2ã®ã»ãã¥ãªãã£ã¢ãããã¼ããå ¬éããã¾ããã å ¬éåããJackson(Javaã§äººæ°ã®ããJSONã©ã¤ãã©ãª)ã®èå¼±æ§ãé¢é£ãã¦ãããã¨ãã話ãã¡ã¼ãªã³ã°ãªã¹ãã«æµãã¦ããã社å ã·ã¹ãã ããã¼ã«ã§Jacksonãå©ç¨ãã¦ããçè ãå ·ä½çã«ã©ã®ãããªå 容ãæ°ã«ãã¦ãã¾ããã https://lists.
{{#tags}}- {{label}}
{{/tags}}