Skip to content

修复spring读取远程配置文件触发RCE漏洞 #5154

@agapple

Description

@agapple

canal依赖spring xml文件来管理IOC依赖,同时允许canal-admin通过web远程管理instance配置,如果有恶意的instance配置会造成Spring的RCE漏洞

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions