We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
审计代码为datagear4.6.0 (https://github.com/datageartech/datagear/tree/v4.6.0) 尝试使用插件复现issuse的漏洞 datageartech/datagear#32
使用sink查找器,RCE下SPEL_RCE的sink类为org.springframework.expression.ExpressionParser#parseExpression(java.lang.String),sink方法为parseExpression。
并不能找到org.datagear.persistence.support.ConversionSqlParamValueMapper#evaluateVariableExpression中的 org.springframework.expression.common.TemplateAwareExpressionParser#parseExpression(java.lang.String)
(如是我使用方式有问题,请忽略这条issue)
The text was updated successfully, but these errors were encountered:
感谢issue,最近太忙忽略了很多issue,后续会跟进修复
Sorry, something went wrong.
No branches or pull requests
审计代码为datagear4.6.0 (https://github.com/datageartech/datagear/tree/v4.6.0)
尝试使用插件复现issuse的漏洞 datageartech/datagear#32
使用sink查找器,RCE下SPEL_RCE的sink类为org.springframework.expression.ExpressionParser#parseExpression(java.lang.String),sink方法为parseExpression。
并不能找到org.datagear.persistence.support.ConversionSqlParamValueMapper#evaluateVariableExpression中的
org.springframework.expression.common.TemplateAwareExpressionParser#parseExpression(java.lang.String)
(如是我使用方式有问题,请忽略这条issue)
The text was updated successfully, but these errors were encountered: