Skip to content

Commit cf4ec57

Browse files
CodeCasterXclaude
andcommitted
fix(fit): 升级 jackson 至 2.21.1 修复异步解析器 DoS 漏洞
修复 Dependabot 安全告警 #26GHSA-72hv-8253-57qq),jackson-core 异步解析器 绕过 maxNumberLength 约束。将 jackson-core/databind 从 2.19.1 升级到 2.21.1, jackson-annotations 升级到 2.21(Jackson 2.20+ annotations 版本策略变更)。 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
1 parent 3255a70 commit cf4ec57

File tree

4 files changed

+6
-5
lines changed
  • framework
    • dependency
    • fit/java
      • fit-builtin/plugins/fit-message-serializer-json-jackson
      • fit-maven-plugin/fit-maven-plugin-util
      • fit-util

4 files changed

+6
-5
lines changed

framework/dependency/pom.xml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,8 @@
5959
<guava.version>32.0.1-jre</guava.version>
6060
<hanlp.version>portable-1.8.4</hanlp.version>
6161
<lombok.version>1.18.36</lombok.version>
62-
<jackson.version>2.19.1</jackson.version>
62+
<jackson.version>2.21.1</jackson.version>
63+
<jackson-annotations.version>2.21</jackson-annotations.version>
6364
<mybatis.version>3.5.19</mybatis.version>
6465

6566
<!-- Test framework versions -->
@@ -474,7 +475,7 @@
474475
<dependency>
475476
<groupId>com.fasterxml.jackson.core</groupId>
476477
<artifactId>jackson-annotations</artifactId>
477-
<version>${jackson.version}</version>
478+
<version>${jackson-annotations.version}</version>
478479
</dependency>
479480
<dependency>
480481
<groupId>com.fasterxml.jackson.core</groupId>

framework/fit/java/fit-builtin/plugins/fit-message-serializer-json-jackson/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919

2020
<properties>
2121
<!-- Third-party versions -->
22-
<jackson.version>2.19.1</jackson.version>
22+
<jackson.version>2.21.1</jackson.version>
2323
</properties>
2424

2525
<dependencies>

framework/fit/java/fit-maven-plugin/fit-maven-plugin-util/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@
1717

1818
<properties>
1919
<!-- Third-party versions -->
20-
<jackson.version>2.19.1</jackson.version>
20+
<jackson.version>2.21.1</jackson.version>
2121
<lombok.version>1.18.36</lombok.version>
2222
</properties>
2323

framework/fit/java/fit-util/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@
1717

1818
<properties>
1919
<!-- Third-party versions -->
20-
<jackson.version>2.19.1</jackson.version>
20+
<jackson.version>2.21.1</jackson.version>
2121
</properties>
2222

2323
<dependencies>

0 commit comments

Comments
 (0)