From 524ad4e6ddc04f2f0cfacb33f42c2f022629bbbb Mon Sep 17 00:00:00 2001 From: abbfun <819589789@qq.com> Date: 星期一, 23 五月 2022 15:36:18 +0800 Subject: [PATCH] fastjson 版本升级 fastjson <= 1.2.80 存在反序列化任意代码执行漏洞 --- ruoyi-framework/src/main/java/com/ruoyi/framework/aspectj/LogAspect.java | 11 ++++++++--- 1 files changed, 8 insertions(+), 3 deletions(-) diff --git a/ruoyi-framework/src/main/java/com/ruoyi/framework/aspectj/LogAspect.java b/ruoyi-framework/src/main/java/com/ruoyi/framework/aspectj/LogAspect.java index 10fa58f..c9ce322 100644 --- a/ruoyi-framework/src/main/java/com/ruoyi/framework/aspectj/LogAspect.java +++ b/ruoyi-framework/src/main/java/com/ruoyi/framework/aspectj/LogAspect.java @@ -65,7 +65,6 @@ { try { - // 获取当前的用户 LoginUser loginUser = SecurityUtils.getLoginUser(); @@ -167,8 +166,14 @@ { if (StringUtils.isNotNull(o) && !isFilterObject(o)) { - Object jsonObj = JSON.toJSON(o); - params += jsonObj.toString() + " "; + try + { + Object jsonObj = JSON.toJSON(o); + params += jsonObj.toString() + " "; + } + catch (Exception e) + { + } } } } -- Gitblit v1.9.2