← All tasks
javaalibaba/nacos #15025Not a task: already works

Nacos Server2.5.2版本引入的组件hessian-3.3.6.jar扫描发现CVE-2024-46983漏洞

envgap__alibaba__nacos-15025

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
881658a2decce46dbb938818f3b71c2396f8f637
Manifest
pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

alibaba/nacos #15025 · read the original issue
Nacos Server2..5.2版本进行安全漏洞扫描时发现以下漏洞:
CVE-2023-35116 | FasterXML jackson-databind 安全漏洞(CVE-2023-35116) | 中危 | jackson-databind-2.13.5.jar
CVE-2024-38816 | Spring 目录遍历漏洞(CVE-2024-38816) | 低危 | spring-webmvc-5.3.39.jar
CVE-2024-46983 | SOFA-Hessian 注入漏洞(CVE-2024-46983) | 严重 | hessian-3.3.6.jar
CVE-2025-48924 | Apache Commons Lang 安全漏洞(CVE-2025-48924) | 低危 | commons-lang-2.6.jar
CVE-2025-52999 | FasterXML jackson-core 安全漏洞(CVE-2025-52999) | 低危 | jackson-core-2.13.5.jar


近期有对Nacos Server2.5.2版本升级组件的计划吗
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]