Skip to content

arthas 4.0.4 被扫描出安全漏洞 #2986

@gtyd

Description

@gtyd
  • 我已经在 issues 里搜索,没有重复的issue。

我们将arthas的jar包,集成到我们应用的Dockerfile中,方便在应用在运行中过程中做故障诊断,版本如下:

Manifest-Version: 1.0
Created-By: core engine team, middleware group, alibaba inc.
Build-Jdk-Spec: 21
Main-Class: com.taobao.arthas.boot.Bootstrap
Implementation-Title: arthas-boot
Implementation-Version: 4.0.4
Specification-Title: arthas-boot
Specification-Version: 4.0.4

但最近被安全团队扫描出有中危漏洞

Image

其指向的是这个版本

Image

具体漏洞描述链接:

https://www.oscs1024.com/hd/MPS-4bv1-8ho6

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions