Nacos Server2.5.2版本引入的组件hessian-3.3.6.jar扫描发现CVE-2024-46983漏洞
envgap__alibaba__nacos-15025
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
881658a2decce46dbb938818f3b71c2396f8f637- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
alibaba/nacos #15025 · read the original issue
Nacos Server2..5.2版本进行安全漏洞扫描时发现以下漏洞: CVE-2023-35116 | FasterXML jackson-databind 安全漏洞(CVE-2023-35116) | 中危 | jackson-databind-2.13.5.jar CVE-2024-38816 | Spring 目录遍历漏洞(CVE-2024-38816) | 低危 | spring-webmvc-5.3.39.jar CVE-2024-46983 | SOFA-Hessian 注入漏洞(CVE-2024-46983) | 严重 | hessian-3.3.6.jar CVE-2025-48924 | Apache Commons Lang 安全漏洞(CVE-2025-48924) | 低危 | commons-lang-2.6.jar CVE-2025-52999 | FasterXML jackson-core 安全漏洞(CVE-2025-52999) | 低危 | jackson-core-2.13.5.jar 近期有对Nacos Server2.5.2版本升级组件的计划吗
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]