FastJson 1.2.83 @JsonType RCE漏洞分析

FastJson 1.2.83 @JsonType RCE漏洞分析

漏洞原理 该漏洞的实现方式并不是和传统fastjson类似通过反序列化时会触发类的setter和getter方法实现,而是利用parse过程中checkAutoType会替换resource中的.为/+spring fat jar使用LaunchedURLClassLoader为类加载器(支持jar

FastJson反序列化 JdbcRowSetImpl JNDI利用链

FastJson反序列化 JdbcRowSetImpl JNDI利用链

Fastjson反序列化jndi注入代码分析

FastJson基础分析

FastJson基础分析

Fastjson反序列化链基础分析