Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider to upgrade to use fastjson 1.2.58 #4575

Closed
2 tasks done
biyuhao opened this issue Jul 15, 2019 · 1 comment · Fixed by #4579
Closed
2 tasks done

Consider to upgrade to use fastjson 1.2.58 #4575

biyuhao opened this issue Jul 15, 2019 · 1 comment · Fixed by #4579

Comments

@biyuhao
Copy link
Member

biyuhao commented Jul 15, 2019

  • I have searched the issues of this repository and believe that this is not a duplicate.
  • I have checked the FAQ of this repository and believe that this is not a duplicate.

Environment

  • Dubbo version: master branch
  • Operating System version: all
  • Java version: all

Steps to reproduce this issue

fastjson <= 1.2.48 considers vulnerable, see https://www.anquanke.com/post/id/181874
we are using 1.2.46, I think it's better to use the latest version fastjson-1.2.58 if possible.

@cvictory
Copy link
Contributor

Can you fire a pull request?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants