hh44h1144
2021-03-12 c0f1569ad98aa44bd4ee2712ff1f3de974a28091
修复commons-collections引起的反序列化漏洞
2 files modified
18 ■■■■ changed files
pom.xml 12 ●●●●● patch | view | raw | blame | history
ruoyi-generator/pom.xml 6 ●●●● patch | view | raw | blame | history
pom.xml
@@ -136,8 +136,18 @@
                <groupId>org.apache.velocity</groupId>
                <artifactId>velocity</artifactId>
                <version>${velocity.version}</version>
                <exclusions>
                    <exclusion>
                        <groupId>commons-collections</groupId>
                        <artifactId>commons-collections</artifactId>
                    </exclusion>
                </exclusions>
            </dependency>
            <dependency>
                <groupId>commons-collections</groupId>
                <artifactId>commons-collections</artifactId>
                <version>3.2.2</version>
            </dependency>
            <!-- 阿里JSON解析器 -->
            <dependency>
                <groupId>com.alibaba</groupId>
ruoyi-generator/pom.xml
@@ -22,7 +22,11 @@
            <groupId>org.apache.velocity</groupId>
            <artifactId>velocity</artifactId>
        </dependency>
        <!--commons-collections-->
        <dependency>
            <groupId>commons-collections</groupId>
            <artifactId>commons-collections</artifactId>
        </dependency>
        <!-- 通用工具-->
        <dependency>
            <groupId>com.ruoyi</groupId>