Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!

ÓÖÒ»¡±ºËµ¯¼¶¡±Îó²î£¿£¿£¿ £¿£¿£¿fastjsonÎó²îÓ°ÏìÉî¶ÈÕÉÁ¿

ʱ¼ä£º2022-05-25 ×÷ÕߣºÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÊÖÒÕÑо¿Ôº

·ÖÏíµ½£º

    2022Äê5ÔÂ23ÈÕ £¬ £¬£¬£¬£¬fastjson¹Ù·½Ðû²¼Ç徲ת´ï £¬ £¬£¬£¬£¬1.2.80¼°ÒÔϰ汾±£´æ·´ÐòÁл¯í§Òâ´úÂëÖ´ÐÐÎó²î £¬ £¬£¬£¬£¬ÔÚÌØ¶¨Ìõ¼þÏ¿ÉÈÆ¹ýĬÈÏautoType¹Ø±ÕÏÞÖÆ £¬ £¬£¬£¬£¬¿ÉÄܻᵼÖÂÔ¶³ÌЧÀÍÆ÷±»¹¥»÷ £¬ £¬£¬£¬£¬Îó²îÆ·¼¶Îª¸ßΣ £¬ £¬£¬£¬£¬Î£º¦Ó°Ïì½Ï´ó[1]¡£¡£ ¡£¡£¡£

    fastjsonÊÇJava¡¢AndroidµÈƽ̨ÆÕ±éʹÓõÄJSONÆÊÎö¿â £¬ £¬£¬£¬£¬´ó×ÚÏîÄ¿½«Æä×÷ΪÒÀÀµ £¬ £¬£¬£¬£¬¿ÉνJavaÉú̬×îΪ³£ÓõĻù´¡¿âÖ®Ò»¡£¡£ ¡£¡£¡£´ËÎó²îÊÂʵÔì³É¶à´óµÄÓ°Ï죿£¿£¿ £¿£¿£¿Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÊÖÒÕÑо¿ÔºÐÇͼʵÑéÊÒʹÓÃ×ÔÑеēÌìÎÊ”Èí¼þ¹©Ó¦Á´Æ½Ì¨¶ÔÆä¾ÙÐÐÁËÉî¶ÈÍÚ¾òÆÊÎö¡£¡£ ¡£¡£¡£

    1?

    fastjsonÎó²îÓ°ÏìÓжàÆÕ±é£¿£¿£¿ £¿£¿£¿

    ÔÚMavenCentralÕâÒ»Java×îÖ÷ÒªµÄ¿ÍÕ»ÖÐ £¬ £¬£¬£¬£¬¹²ÓнüÍò¸öJava°üÊܵ½fastjsonÎó²îÓ°Ïì £¬ £¬£¬£¬£¬Õ¼°ü×ÜÁ¿µÄ2.13%¡£¡£ ¡£¡£¡£

    ×èÖ¹2022Äê5ÔÂ24ÈÕ £¬ £¬£¬£¬£¬ÎÒÃÇ·¢Ã÷MavenCentralÖеÄ9,902¸öJava°üÒÀÀµÓÚ°üÀ¨Îó²îµÄfastjson°æ±¾ £¬ £¬£¬£¬£¬ÕâÒâζ×ÅMavenCentralÉÏÔ¼2.13%µÄÈí¼þ°üÖÁÉÙÓÐÒ»¸ö°æ±¾Êܵ½´ËÎó²îÍþв¡£¡£ ¡£¡£¡£ÈôÊÇ˵ȥÄêµ×±¬³ölog4jÔ¶³Ì´úÂëÖ´ÐÐÎó²îÊÇÒ»¿Å´óÐͺ˵¯µÄ»°£¨Ó°ÏìÁËÔ¼17,000¸öJava°ü £¬ £¬£¬£¬£¬Õ¼±ÈÔ¼4%£© £¬ £¬£¬£¬£¬fastjsonµÄÎó²îÓ°Ïì²»ÑÇÓÚÒ»¿ÅÖÐÐͺ˵¯ÁË¡£¡£ ¡£¡£¡£

    ÔÚMavenCentralÉÏ £¬ £¬£¬£¬£¬Ö±½ÓÒÀÀµÁËfastjsonÎó²î°æ±¾µÄJavaÈí¼þ°üÊýÄ¿µÖ´ïÁË3,845¸ö £¬ £¬£¬£¬£¬Õ¼µ½ËùÓÐÊÜÓ°ÏìJava°üµÄ38.8% £¬ £¬£¬£¬£¬Ò²¾ÍÊÇ˵ £¬ £¬£¬£¬£¬Óиߴï61.2%µÄJava°ü¼ä½ÓÒÀÀµÁËfastjson£¨¼´×ÔÉíÒÀÀµµÄÒ»¸öÈí¼þ°üÒÀÀµÁËfastjson£©¡£¡£ ¡£¡£¡£

ÓÖÒ»”ºËµ¯¼¶”Îó²î£¿£¿£¿£¿£¿£¿fastjsonÎó²îÓ°ÏìÉî¶ÈÕÉÁ¿

    Í¼1Ö±½ÓÒÀÀµÎó²îÈí¼þ°ü£¨×󣩺ͼä½ÓÒÀÀµÎó²îÈí¼þ°ü£¨ÓÒ£©ÈªÔ´:GoogleSecurityBlog

    2?

    ÓÐÄÄЩÖ÷ÒªÏîÄ¿ÊÜÓ°Ï죿£¿£¿ £¿£¿£¿

    ÆÊÎö·¢Ã÷ApacheDubbo¡¢RocketMQ¡¢Beam £¬ £¬£¬£¬£¬°¢Àï°Í°ÍNacos¡¢Sentinel¡¢¾©¶«ÔÆJavaSDKµÈÖ÷ÒªÏîÄ¿ÒÀÀµÁ˺¬Îó²îµÄfastjson°æ±¾ £¬ £¬£¬£¬£¬Ê¹ÓÃÕâЩÏîÄ¿µÄ¿ª·¢ÕßÐèÒªÇ×½ü¹Ø×¢Îó²îÐÞ¸´Ï£Íû £¬ £¬£¬£¬£¬ÊµÊ±¸üе½²¹¶¡°æ±¾¡£¡£ ¡£¡£¡£

ÓÖÒ»”ºËµ¯¼¶”Îó²î£¿£¿£¿£¿£¿£¿fastjsonÎó²îÓ°ÏìÉî¶ÈÕÉÁ¿

    3?

    ´ËÎó²îÐÞ¸´ÄÑÌâÂ𣿣¿£¿ £¿£¿£¿

    Ö±½ÓʹÓÃÁËfastjsonµÄÏîÄ¿ÐÞ¸´²»ÄÑ¡£¡£ ¡£¡£¡£

    ¼ä½ÓÒÀÀµÁËfastjsonµÄÏîÄ¿ £¬ £¬£¬£¬£¬ÒÀÀµ²ã¼¶Ô½Éî £¬ £¬£¬£¬£¬ÐÞ¸´ËùÐè°ì·¨¾ÍÔ½¶à¡¢ÄѶÈÔ½´ó¡£¡£ ¡£¡£¡£

    Í¼2ÏÔʾÁËÊÜÓ°ÏìµÄJavaÈí¼þ°üÒÀÀµÓÚfastjsonµÄ²ã¼¶ £¬ £¬£¬£¬£¬²ã¼¶Îª1´ú±íÖ±½ÓÒÀÀµ¡£¡£ ¡£¡£¡£¿£¿£¿ £¿£¿£¿ÉÒÔ¿´µ½ £¬ £¬£¬£¬£¬¸ß´ï61.2%µÄJava°üÒÀÀµ²ã¼¶Áè¼Ý1¼¶ £¬ £¬£¬£¬£¬ÓÐÁè¼Ý500¸öJava°üµÄÒÀÀµ²ã¼¶Áè¼ÝÁË5¼¶ £¬ £¬£¬£¬£¬²ã¼¶×îÉîµÄÈí¼þ°ü£¨Èçͼ3Ëùʾ£©µÄÒÀÀµÉî¶ÈÉõÖÁ¸ß´ï10¼¶¡£¡£ ¡£¡£¡£¶ÔÕâЩ°üµÄÐÞ¸´ £¬ £¬£¬£¬£¬ÐèÒª½«ÒÀÀµÁ´ÌõÖеÄËùÓв㼶ÖðÒ»¾ÙÐÐÐÞ¸´ £¬ £¬£¬£¬£¬Òò´ËÄѶȽϴ󡣡£ ¡£¡£¡£

    ²Î¿¼log4jÎó²îµÄÐÞ¸´Ê±¼ä £¬ £¬£¬£¬£¬ÔÚÎó²îÅû¶µÄÒ»ÖÜʱ¼äÄÚ £¬ £¬£¬£¬£¬½öÓÐԼĪ13%Êܵ½Ó°ÏìµÄÈí¼þ°ü»ñµÃÁËÐÞ¸´[2] £¬ £¬£¬£¬£¬ÕâҲΪÈí¼þ¿ª·¢Õß¡¢Çå¾²´ÓÒµÕßÇÃÏìÁ˾¯ÖÓ £¬ £¬£¬£¬£¬¿ÉÄÜδÀ´Ò»¶Îʱ¼äÄÚ £¬ £¬£¬£¬£¬Õë¶ÔfastjsonÎó²îµÄ¹¥»÷½«Ê±Óб¬·¢¡£¡£ ¡£¡£¡£

ÓÖÒ»”ºËµ¯¼¶”Îó²î£¿£¿£¿£¿£¿£¿fastjsonÎó²îÓ°ÏìÉî¶ÈÕÉÁ¿

    Í¼2ÊÜÓ°ÏìµÄJavaÈí¼þ°üµÄÒÀÀµ²ã¼¶¼°¶ÔÓ¦ÊýÄ¿

ÓÖÒ»”ºËµ¯¼¶”Îó²î£¿£¿£¿£¿£¿£¿fastjsonÎó²îÓ°ÏìÉî¶ÈÕÉÁ¿

    Í¼3top.wboost:webmvc-spring-boot-starterÈí¼þ°ü¶ÔfastjsonµÄÒÀÀµÉî¶ÈµÖ´ï10¼¶

    4?

    ÐÞ¸´½¨Òé

    1.¸üе½1.2.83¼°ÒÔÉϰ汾

    ¿Éͨ¹ýMaven°ü¹ÜÀí¹¤¾ß¸üС¢ÊÖ¶¯¸üÐÂÖÁÇå¾²ÐÞ¸´°æ±¾Á½ÖÖ·½·¨ÊµÏÖ¸üР£¬ £¬£¬£¬£¬GitHub¿ªÔ´ÏîÄ¿×îеÄÇå¾²ÐÞ¸´°æ±¾ÏÂÔØµØµã£º

    https://github.com/alibaba/fastjson/releases/tag/1.2.83

    2.¿ªÆôsafeMode¹¦Ð§

    fastjsonÔÚ1.2.68¼°Ö®ºóµÄ°æ±¾ÖÐÒýÈëÁËsafeMode £¬ £¬£¬£¬£¬ÉèÖÃsafeModeºó £¬ £¬£¬£¬£¬ÎÞÂÛ°×Ãûµ¥ºÍºÚÃûµ¥ £¬ £¬£¬£¬£¬¶¼²»Ö§³ÖautoType £¬ £¬£¬£¬£¬¿É¶Å¾ø·´ÐòÁл¯GadgetsÀà±äÖÖ¹¥»÷£¨¹Ø±ÕautoType×¢ÖØÆÀ¹À¶ÔÓªÒµµÄÓ°Ï죩,ÓÐÈýÖÖ·½·¨ÉèÖÃSafeMode[3]£º

    £¨1£©ÔÚ´úÂëÖÐÉèÖÃ

    ParserConfig.getGlobalInstance().setSafeMode(true);

    £¨2£©¼ÓÉÏJVMÆô¶¯²ÎÊý

    -Dfastjson.parser.safeMode=true

    £¨3£©Í¨¹ýfastjson.propertiesÎļþÉèÖÃ

    Í¨¹ýÀà·¾¶µÄfastjson.propertiesÎļþÀ´ÉèÖà £¬ £¬£¬£¬£¬ÉèÖ÷½·¨ÈçÏ£º

    fastjson.parser.safeMode=true

    3.Éý¼¶µ½fastjsonv2

    fastjsonÒѾ­¿ªÔ´2.0°æ±¾ £¬ £¬£¬£¬£¬ÔÚ2.0°æ±¾ÖÐ £¬ £¬£¬£¬£¬²»ÔÙΪÁ˼æÈÝÌṩ°×Ãûµ¥ £¬ £¬£¬£¬£¬ÌáÉýÁËÇå¾²ÐÔ¡£¡£ ¡£¡£¡£fastjsonv2´úÂëÒѾ­ÖØÐ´ £¬ £¬£¬£¬£¬ÐÔÄÜÓÐÁ˺ܴóÌáÉý £¬ £¬£¬£¬£¬²»ÍêÈ«¼æÈÝ1.x £¬ £¬£¬£¬£¬Éý¼¶ÐèÒª×öÈÏÕæµÄ¼æÈݲâÊÔ¡£¡£ ¡£¡£¡£


    ²Î¿¼Á´½Ó

    [1]fastjsonsecurityupdate(2020-05-23),https://github.com/alibaba/fastjson/wiki/security_update_20220523.

    [2]UnderstandingtheImpactofApacheLog4jVulnerability,https://security.googleblog.com/2021/12/understanding-impact-of-apache-log4j.html.

    [3]Enablefastjsonsafemode,https://github.com/alibaba/fastjson/wiki/fastjson_safemode.

    “ÌìÎÊ”ÊÇÓÉÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÊÖÒÕÑо¿ÔºÐÇͼʵÑéÊÒ¿ª·¢µÄÈí¼þ¹©Ó¦Á´Çå¾²ÆÊÎöƽ̨ £¬ £¬£¬£¬£¬×¨×¢ÓÚÈí¼þ¹©Ó¦Á´Éú̬µÄÇ徲Σº¦Ê¶±ðÓë¼ì²â¡£¡£ ¡£¡£¡£

    ÎÒÃÇÏÖÔÚÕýÔÚÕÐÆ¸ £¬ £¬£¬£¬£¬ÊÂÇéËùÔÚÁýÕÖ±±¾©¡¢ÉϺ£¡¢ÄϾ©¡¢³É¶¼µÈ¶¼»á £¬ £¬£¬£¬£¬ÏêÇéÇë°Ý¼û£º

    https://research.qianxin.com/recruitment/

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015ÍøÂçÇ徲ЧÀÍÈÈÏß

95015ÍøÂçÇ徲ЧÀÍÈÈÏß

ɨһɨ¹Ø×¢

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! ÔÚÏ߿ͷþ Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015

Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ

ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿