← All tasks
javaalibaba/arthas #3260Not a task: not reproduced

升级 fastjson2 至 2.0.64,修复 AutoType 安全漏洞

envgap__alibaba__arthas-3260

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
a5ecd7a84a93da8761b396fae2eee95301b3d6ff
Manifest
pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

alibaba/arthas #3260 · read the original issue
- [x] 我已经在 [issues](https://github.com/alibaba/arthas/issues) 里搜索,没有重复的 issue。

### 问题说明

当前 master 依赖的 `com.alibaba.fastjson2:fastjson2` 版本为 **2.0.58**。

fastjson2 **2.0.63** 是安全修复版本,加固了 AutoType 反序列化校验,并修复了多个可由构造输入触发的解析健壮性问题(OOM / DoS)。官方建议所有用户尽快升级,尤其是解析不可信 JSON / JSONB 的场景。

相关说明:
- [fastjson2 2.0.63 Release Notes](https://github.com/alibaba/fastjson2/releases/tag/2.0.63)
- [fastjson2#7702](https://github.com/alibaba/fastjson2/issues/7702)

2.0.63 主要修复:
1. 加强 AutoType 类型名校验与白名单验证(含 URL 特殊字符拒绝、白名单 hash 文本回验、accept 前缀不再覆盖危险基类)
2. 限制超长数字字面量,避免 `BigInteger` DoS
3. 修复 JSONB 声明长度导致的 OOM

2.0.64 是目前最新的 bugfix 版本,建议直接升到最新。

### 期望的结果

将依赖升级到 `fastjson2` **2.0.64**。

### 实际运行的结果

Arthas 仍使用 2.0.58,未包含上述安全修复。
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]