Skip to content

[Bug]: fastjson已经是1.2.83版本了,洞态显示请求头有反序列化漏洞 #533

@PhuketIsland

Description

@PhuketIsland

Preflight Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for an issue that matches the one I want to file, without success.
  • I am not looking for support or already pursued the available support channels without success.

Version

1.11.0

Installation Type

Official SaaS Service

Service Name

DongTai-agent-java

Describe the details of the bug and the steps to reproduce it

image
污点流程图
image
危险方法显示是fastjson
image
但是fastjson目前已经是最新版本 1.2.83 ,这是否是误报?不是误报的话又该怎么验证

Additional Information

No response

Logs

No response

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions