Áú8¹ú¼Êµç×Óƽ̨

long8-Áú8(¹ú¼Ê)Ψһ¹Ù·½ÍøÕ¾ Ê×Ò³long8-Áú8(¹ú¼Ê)Ψһ¹Ù·½ÍøÕ¾Çå¾²·þÎñlong8-Áú8(¹ú¼Ê)Ψһ¹Ù·½ÍøÕ¾Ç徲ͨ¸æ long8-Áú8(¹ú¼Ê)Ψһ¹Ù·½ÍøÕ¾
ÕýÎÄ

FastjsonÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇå¾²Ô¤¾¯Ó뽨Òé

Ðû²¼Ê±¼ä£º2022-05-25 16:05   ä¯ÀÀ´ÎÊý£º5100

¿ËÈÕ£¬Áú8¹ú¼Êµç×Óƽ̨ÐÅÏ¢Çå¾²ÍþвÇ鱨ÖÐÐļà²âµ½°¢Àï°Í°Í¹«Ë¾¿ªÔ´Java¿ª·¢×é¼þFastjson±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷ÕßʹÓÃÉÏÊöÎó²î¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£ÏÖÔÚ¹Ù·½ÒÑÐû²¼Çå¾²°æ±¾£¬Áú8¹ú¼Êµç×Óƽ̨ÐÅÏ¢Çå¾²Ó¦¼±ÖÐÐĽ¨ÒéÊÜÓ°Ï쵥λºÍÓû§Á¬Ã¦Éý¼¶ÖÁÇå¾²°æ±¾¡£


Ò»¡¢Îó²îÐÎò

FastjsonÊÇ°¢Àï°Í°Í¿ªÔ´µÄJava¹¤¾ßºÍJSONÃûÌÃ×Ö·û´®µÄ¿ìËÙת»»µÄ¹¤¾ß¿â¡£Ëü¿ÉÒÔÆÊÎöJSONÃûÌõÄ×Ö·û´®£¬Ö§³Ö½«Java BeanÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean¡£Ïà¹ØFastjson°æ±¾±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¹¥»÷Õß¿ÉÒÔÔÚÌض¨ÒÀÀµÏÂʹÓôËÎó²îÈƹýĬÈÏautoType¹Ø±ÕÏÞÖÆ£¬´Ó¶ø·´ÐòÁл¯ÓйØÇ徲Σº¦µÄÀà¡£ÔÚÌض¨Ìõ¼þÏ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£


¶þ¡¢Ó°Ïì¹æÄ£

ÊÜÓ°ÏìµÄ²úÆ·¼°°æ±¾£º

Ìض¨ÒÀÀµ±£´æÏÂÓ°Ïì Fastjson ¡Ü1.2.80


Èý¡¢Çå¾²Ìá·À½¨Òé

Áú8¹ú¼Êµç×Óƽ̨ÐÅÏ¢ÌáÐѸ÷Ïà¹Øµ¥Î»ºÍÓû§ÒªÇ¿»¯Î£º¦Òâʶ£¬ÇÐʵÔöÇ¿Çå¾²Ìá·À£º

1¡¢ÏÖÔÚºÚ¶ÜWebÓ¦Ó÷À»ðǽ¡¢ºÚ¶ÜÈëÇÖ¼ì²âϵͳ¡¢ºÚ¶ÜÈëÇÖ·ÀÓùϵͳµÈÇå¾²×°±¸Ö§³ÖÎó²î·ÀÓù¼°Ïà¹ØÎó²îµÄ¼ì²â£º


6626262.png

ÈçÏà¹ØÓû§×°±¸¹æÔò¿âδÉý¼¶ÖÁ×îйæÔò¿â£¬ÇëʵʱÉý¼¶×°±¸¹æÔò¿â°æ±¾£¬Ïà¹ØÌØÕ÷¿âÒÑÐû²¼µ½¹ÙÍø

http://www.si.net.cn/Technical/upgrade.html

2¡¢ÏÖÔÚ¹Ù·½ÒÑÐû²¼Çå¾²°æ±¾£º1.2.83£¬Áú8¹ú¼Êµç×Óƽ̨ÐÅÏ¢ÌáÐѸ÷Ïà¹Øµ¥Î»ºÍÓû§ÒªÇ¿»¯Î£º¦Òâʶ£¬ÇÐʵÔöÇ¿Çå¾²Ìá·À£º

½¨ÒéÓû§¾¡¿ì×Բ飬¶ÔÊÜÓ°ÏìµÄ°æ±¾ÊµÊ±Éý¼¶ÖÁ×îа汾1.2.83£ºhttps://github.com/alibaba/fastjson/releases/tag/1.2.83

3¡¢ÉèÖÃsafeMode

FastjsonÔÚ 1.2.68 ¼°Ö®ºóµÄ°æ±¾ÖÐÒýÈëÁË safeMode£¬ÉèÖà safeMode ºó£¬ÎÞÂÛ°×Ãûµ¥ºÍºÚÃûµ¥£¬¶¼²»Ö§³Ö autoType£¬¿É¶Å¾ø´ËÀà·´ÐòÁл¯Îó²î¹¥»÷£¨¹Ø±ÕautoType×¢ÖØÆÀ¹À¶ÔÓªÒµµÄÓ°Ï죩¡£Òò´Ë 1.2.68 ¼°Ö®ºó°æ±¾µÄÓû§ÈôÎÞ·¨Í¨¹ý°æ±¾Éý¼¶À´ÐÞ¸´Îó²î£¬¿É˼Á¿ÉèÖÿªÆô safeMode£¬ÈçÏÂÌṩÈýÖÖÉèÖÃSafeModeµÄÒªÁ죺

a¡¢ÔÚÏìÓ¦ÓÐÒýÈëFastjson×é¼þµÄ´úÂëÖУ¬ÉèÖüÓÈëÈçÏ´úÂ룺ParserConfig.getGlobalInstance().setSafeMode(true)

b¡¢Í¨¹ýfastjson.propertiesÎļþÉèÖã¬ÔÚÉèÖÃÎļþÖмÓÈëÈçÏ£ºfastjson.parser.safeMode=true

c¡¢¼ÓÉÏJVMÆô¶¯²ÎÊý£º-Dfastjson.parser.safeMode=true

ÏêϸÉèÖÃÒªÁì¿É²Î¿¼£ºhttps://github.com/alibaba/fastjson/wiki/fastjson_safemode

 

¸½²Î¿¼Á´½Ó£º

https://www.cnvd.org.cn/flaw/show/CNVD-2022-40233

Áú8¹ú¼Êµç×Óƽ̨ °æȨËùÓÐ  ÁªÏµ: hxzhb@heidun.net ÃöICP±¸06011901ºÅ ? 1999-2024 Fujian Strait Information Corporation. All Rights Reserved.
long8-Áú8(¹ú¼Ê)Ψһ¹Ù·½ÍøÕ¾

·µ»Ø¶¥²¿

ÍøÕ¾µØͼ