Skip to content

Commit 6ccbc8a

Browse files
committed
🍺 Java Sec
1 parent 1af3663 commit 6ccbc8a

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

55 files changed

+2247
-463
lines changed

.gitignore

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,11 +2,12 @@
22
.vscode
33
/logs/
44
/target/
5+
/out
56
.apt_generated
67
.classpath
78
.factorypath
89
.project
910
.settings
1011
.springBeans
1112
.sts4-cache
12-
.DS_Store
13+
.DS_Store

Dockerfile

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
FROM java:8
2+
3+
VOLUME /tmp
4+
5+
ADD hello-1.0.0-SNAPSHOT.jar app.jar
6+
7+
EXPOSE 8888
8+
9+
RUN sh -c 'touch /app.jar'
10+
11+
ENTRYPOINT ["java","-Djava.security.egd=file:/dev/./urandom","-jar","/app.jar"]

META-INF/MANIFEST.MF

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
Manifest-Version: 1.0
2+
Main-Class:
3+
Class-Path: groovy-console-2.5.14.jar ant-antlr-1.9.15.jar mybatis-sprin
4+
g-boot-starter-2.1.4.jar springfox-core-2.9.2.jar jcommander-1.72.jar f
5+
astjson-1.2.24.jar log4j-core-2.13.3.jar LatencyUtils-2.0.3.jar HdrHist
6+
ogram-2.1.12.jar swagger-models-1.5.20.jar spring-core-5.3.2.jar unbesc
7+
ape-1.1.6.RELEASE.jar logback-core-1.2.3.jar spring-aop-5.3.2.jar sprin
8+
gfox-spring-web-2.9.2.jar jsoup-1.12.2.jar jackson-databind-2.11.3.jar
9+
groovy-json-2.5.14.jar groovy-nio-2.5.14.jar picocli-4.3.2.jar spring-c
10+
ontext-5.3.2.jar jdom2-2.0.6.jar commons-lang-2.4.jar spring-boot-start
11+
er-json-2.4.1.jar springfox-swagger-common-2.9.2.jar groovy-sql-2.5.14.
12+
jar junit-4.13.1.jar jakarta.el-3.0.3.jar groovy-testng-2.5.14.jar guav
13+
a-20.0.jar json-simple-1.1.1.jar thymeleaf-extras-java8time-3.0.4.RELEA
14+
SE.jar spring-boot-starter-logging-2.4.1.jar mybatis-spring-boot-autoco
15+
nfigure-2.1.4.jar groovy-cli-commons-2.5.14.jar groovy-datetime-2.5.14.
16+
jar byte-buddy-1.10.18.jar groovy-2.5.14.jar junit-jupiter-api-5.7.0.ja
17+
r jakarta.annotation-api-1.3.5.jar testng-6.13.1.jar jackson-core-2.11.
18+
3.jar springfox-spi-2.9.2.jar groovy-jmx-2.5.14.jar spring-beans-5.3.2.
19+
jar junit-platform-commons-1.7.0.jar HikariCP-3.4.5.jar jackson-datatyp
20+
e-jsr310-2.11.3.jar swagger-annotations-1.5.20.jar log4j-api-2.13.3.jar
21+
tomcat-embed-websocket-9.0.41.jar classmate-1.5.1.jar junit-platform-e
22+
ngine-1.7.0.jar commons-collections-3.2.1.jar groovy-docgenerator-2.5.1
23+
4.jar jul-to-slf4j-1.7.30.jar spring-boot-starter-2.4.1.jar spring-jcl-
24+
5.3.2.jar ant-junit-1.9.15.jar groovy-ant-2.5.14.jar springfox-swagger-
25+
ui-2.10.5.jar groovy-groovydoc-2.5.14.jar jackson-module-parameter-name
26+
s-2.11.3.jar commons-cli-1.4.jar spring-boot-devtools-2.4.1.jar snakeya
27+
ml-1.27.jar groovy-cli-picocli-2.5.14.jar logback-classic-1.2.3.jar thy
28+
meleaf-spring5-3.0.11.RELEASE.jar mapstruct-1.2.0.Final.jar jackson-dat
29+
atype-jdk8-2.11.3.jar micrometer-core-1.6.2.jar log4j-to-slf4j-2.13.3.j
30+
ar spring-boot-actuator-2.4.1.jar attoparser-2.0.5.RELEASE.jar hamcrest
31+
-core-2.2.jar spring-tx-5.3.2.jar spring-web-5.3.2.jar groovy-macro-2.5
32+
.14.jar groovy-xml-2.5.14.jar junit-platform-launcher-1.7.0.jar xpp3_mi
33+
n-1.1.4c.jar groovy-test-2.5.14.jar spring-boot-starter-jdbc-2.4.1.jar
34+
ant-launcher-1.9.15.jar spring-boot-starter-thymeleaf-2.4.1.jar spring-
35+
webmvc-5.3.2.jar tomcat-embed-core-9.0.41.jar spring-boot-autoconfigure
36+
-2.4.1.jar spring-boot-2.4.1.jar slf4j-api-1.7.30.jar ant-1.9.15.jar my
37+
batis-spring-2.0.6.jar thymeleaf-3.0.11.RELEASE.jar groovy-swing-2.5.14
38+
.jar dom4j-2.1.3.jar apiguardian-api-1.1.0.jar jolokia-core-1.4.0.jar x
39+
mlprojector-1.4.14.jar xstream-1.4.10.jar groovy-jsr223-2.5.14.jar spri
40+
ngfox-swagger2-2.9.2.jar junit-jupiter-engine-5.7.0.jar groovy-servlet-
41+
2.5.14.jar groovy-groovysh-2.5.14.jar spring-plugin-core-1.2.0.RELEASE.
42+
jar spring-boot-starter-actuator-2.4.1.jar velocity-1.7.jar mysql-conne
43+
ctor-java-8.0.22.jar spring-boot-actuator-autoconfigure-2.4.1.jar sprin
44+
g-boot-starter-tomcat-2.4.1.jar spring-expression-5.3.2.jar spring-plug
45+
in-metadata-1.2.0.RELEASE.jar groovy-templates-2.5.14.jar spring-jdbc-5
46+
.3.2.jar hamcrest-2.2.jar jackson-annotations-2.11.3.jar groovy-test-ju
47+
nit5-2.5.14.jar springfox-schema-2.9.2.jar jline-2.14.6.jar xmlpull-1.1
48+
.3.1.jar spring-boot-starter-web-2.4.1.jar qdox-1.12.1.jar opentest4j-1
49+
.2.0.jar mybatis-3.5.6.jar
50+

README.md

Lines changed: 9 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,23 +1,24 @@
11
# ☕️ Hello Java Sec ![Stage](https://img.shields.io/badge/Release-DEV-brightgreen.svg)
2-
> 学习 Java 漏洞,记录一下代码
2+
> Java漏洞平台,结合漏洞代码和安全编码,帮助研发同学理解和减少漏洞
33
4-
![](media/16261597400147.jpg)
4+
![](media/16278906186353.jpg)
55

66

77
- 默认账号:admin/admin
88

99
## Vulnerability
10-
- [ ] SQLi
10+
- [x] SQLi
1111
- [x] XSS
1212
- [x] RCE
13+
- [x] Deserialize
1314
- [x] SSTI
1415
- [x] SpEL
1516
- [x] SSRF
16-
- [ ] Directory Traversal
17+
- [x] Directory Traversal
1718
- [x] Redirect
1819
- [ ] CSRF
1920
- [ ] File Upload
20-
- [ ] XXE
21+
- [x] XXE
2122
- [x] Actuator
2223
- [ ] Fastjson
2324

@@ -33,8 +34,9 @@ spring.datasource.password=1234567
3334
### Jar
3435
```
3536
git clone https://github.com/j3ers3/Hello-Java-Sec
37+
cd Hello-Java-Sec
3638
mvn clean package -DskipTests
37-
java -jar hello-0.0.1-SNAPSHOT.jar
39+
java -jar target/hello-1.0.0-SNAPSHOT.jar
3840
```
3941

4042

@@ -43,4 +45,4 @@ java -jar hello-0.0.1-SNAPSHOT.jar
4345
- SpringBoot 4.0
4446
- Bootstrap 4.6.0
4547
- Codemirror 5.62.0
46-
- Fastjson 1.2.24
48+
- Fastjson 1.2.24

hello.iml

Lines changed: 69 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -31,12 +31,10 @@
3131
<orderEntry type="library" name="Maven: ch.qos.logback:logback-classic:1.2.3" level="project" />
3232
<orderEntry type="library" name="Maven: ch.qos.logback:logback-core:1.2.3" level="project" />
3333
<orderEntry type="library" name="Maven: org.apache.logging.log4j:log4j-to-slf4j:2.13.3" level="project" />
34-
<orderEntry type="library" name="Maven: org.apache.logging.log4j:log4j-api:2.13.3" level="project" />
3534
<orderEntry type="library" name="Maven: org.slf4j:jul-to-slf4j:1.7.30" level="project" />
3635
<orderEntry type="library" name="Maven: jakarta.annotation:jakarta.annotation-api:1.3.5" level="project" />
3736
<orderEntry type="library" name="Maven: org.yaml:snakeyaml:1.27" level="project" />
3837
<orderEntry type="library" name="Maven: com.zaxxer:HikariCP:3.4.5" level="project" />
39-
<orderEntry type="library" name="Maven: org.slf4j:slf4j-api:1.7.30" level="project" />
4038
<orderEntry type="library" name="Maven: org.springframework:spring-jdbc:5.3.2" level="project" />
4139
<orderEntry type="library" name="Maven: org.springframework:spring-beans:5.3.2" level="project" />
4240
<orderEntry type="library" name="Maven: org.springframework:spring-tx:5.3.2" level="project" />
@@ -64,17 +62,17 @@
6462
<orderEntry type="library" scope="TEST" name="Maven: jakarta.xml.bind:jakarta.xml.bind-api:2.3.3" level="project" />
6563
<orderEntry type="library" scope="TEST" name="Maven: jakarta.activation:jakarta.activation-api:1.2.2" level="project" />
6664
<orderEntry type="library" scope="TEST" name="Maven: org.assertj:assertj-core:3.18.1" level="project" />
67-
<orderEntry type="library" scope="TEST" name="Maven: org.hamcrest:hamcrest:2.2" level="project" />
65+
<orderEntry type="library" name="Maven: org.hamcrest:hamcrest:2.2" level="project" />
6866
<orderEntry type="library" scope="TEST" name="Maven: org.junit.jupiter:junit-jupiter:5.7.0" level="project" />
69-
<orderEntry type="library" scope="TEST" name="Maven: org.junit.jupiter:junit-jupiter-api:5.7.0" level="project" />
70-
<orderEntry type="library" scope="TEST" name="Maven: org.apiguardian:apiguardian-api:1.1.0" level="project" />
71-
<orderEntry type="library" scope="TEST" name="Maven: org.opentest4j:opentest4j:1.2.0" level="project" />
72-
<orderEntry type="library" scope="TEST" name="Maven: org.junit.platform:junit-platform-commons:1.7.0" level="project" />
67+
<orderEntry type="library" name="Maven: org.junit.jupiter:junit-jupiter-api:5.7.0" level="project" />
68+
<orderEntry type="library" name="Maven: org.apiguardian:apiguardian-api:1.1.0" level="project" />
69+
<orderEntry type="library" name="Maven: org.opentest4j:opentest4j:1.2.0" level="project" />
70+
<orderEntry type="library" name="Maven: org.junit.platform:junit-platform-commons:1.7.0" level="project" />
7371
<orderEntry type="library" scope="TEST" name="Maven: org.junit.jupiter:junit-jupiter-params:5.7.0" level="project" />
74-
<orderEntry type="library" scope="TEST" name="Maven: org.junit.jupiter:junit-jupiter-engine:5.7.0" level="project" />
75-
<orderEntry type="library" scope="TEST" name="Maven: org.junit.platform:junit-platform-engine:1.7.0" level="project" />
72+
<orderEntry type="library" scope="RUNTIME" name="Maven: org.junit.jupiter:junit-jupiter-engine:5.7.0" level="project" />
73+
<orderEntry type="library" name="Maven: org.junit.platform:junit-platform-engine:1.7.0" level="project" />
7674
<orderEntry type="library" scope="TEST" name="Maven: org.mockito:mockito-core:3.6.28" level="project" />
77-
<orderEntry type="library" scope="TEST" name="Maven: net.bytebuddy:byte-buddy:1.10.18" level="project" />
75+
<orderEntry type="library" name="Maven: net.bytebuddy:byte-buddy:1.10.18" level="project" />
7876
<orderEntry type="library" scope="TEST" name="Maven: net.bytebuddy:byte-buddy-agent:1.10.18" level="project" />
7977
<orderEntry type="library" scope="TEST" name="Maven: org.objenesis:objenesis:3.1" level="project" />
8078
<orderEntry type="library" scope="TEST" name="Maven: org.mockito:mockito-junit-jupiter:3.6.28" level="project" />
@@ -87,7 +85,6 @@
8785
<orderEntry type="library" name="Maven: org.springframework.boot:spring-boot-starter-web:2.4.1" level="project" />
8886
<orderEntry type="library" name="Maven: org.springframework.boot:spring-boot-starter-json:2.4.1" level="project" />
8987
<orderEntry type="library" name="Maven: com.fasterxml.jackson.core:jackson-databind:2.11.3" level="project" />
90-
<orderEntry type="library" name="Maven: com.fasterxml.jackson.core:jackson-annotations:2.11.3" level="project" />
9188
<orderEntry type="library" name="Maven: com.fasterxml.jackson.core:jackson-core:2.11.3" level="project" />
9289
<orderEntry type="library" name="Maven: com.fasterxml.jackson.datatype:jackson-datatype-jdk8:2.11.3" level="project" />
9390
<orderEntry type="library" name="Maven: com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.11.3" level="project" />
@@ -102,7 +99,10 @@
10299
<orderEntry type="library" name="Maven: org.springframework:spring-context:5.3.2" level="project" />
103100
<orderEntry type="library" name="Maven: org.springframework:spring-expression:5.3.2" level="project" />
104101
<orderEntry type="library" name="Maven: com.alibaba:fastjson:1.2.24" level="project" />
105-
<orderEntry type="library" name="Maven: org.springframework.boot:spring-boot-devtools:2.4.1" level="project" />
102+
<orderEntry type="library" name="Maven: com.thoughtworks.xstream:xstream:1.4.10" level="project" />
103+
<orderEntry type="library" name="Maven: xmlpull:xmlpull:1.1.3.1" level="project" />
104+
<orderEntry type="library" name="Maven: xpp3:xpp3_min:1.1.4c" level="project" />
105+
<orderEntry type="library" scope="RUNTIME" name="Maven: org.springframework.boot:spring-boot-devtools:2.4.1" level="project" />
106106
<orderEntry type="library" name="Maven: org.springframework.boot:spring-boot:2.4.1" level="project" />
107107
<orderEntry type="library" name="Maven: org.springframework.boot:spring-boot-autoconfigure:2.4.1" level="project" />
108108
<orderEntry type="library" name="Maven: org.springframework.boot:spring-boot-starter-actuator:2.4.1" level="project" />
@@ -113,5 +113,62 @@
113113
<orderEntry type="library" scope="RUNTIME" name="Maven: org.latencyutils:LatencyUtils:2.0.3" level="project" />
114114
<orderEntry type="library" name="Maven: org.jolokia:jolokia-core:1.4.0" level="project" />
115115
<orderEntry type="library" name="Maven: com.googlecode.json-simple:json-simple:1.1.1" level="project" />
116+
<orderEntry type="library" name="Maven: org.apache.logging.log4j:log4j-core:2.13.3" level="project" />
117+
<orderEntry type="library" name="Maven: org.apache.logging.log4j:log4j-api:2.13.3" level="project" />
118+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy:2.5.14" level="project" />
119+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-ant:2.5.14" level="project" />
120+
<orderEntry type="library" name="Maven: org.apache.ant:ant:1.9.15" level="project" />
121+
<orderEntry type="library" scope="RUNTIME" name="Maven: org.apache.ant:ant-junit:1.9.15" level="project" />
122+
<orderEntry type="library" name="Maven: org.apache.ant:ant-launcher:1.9.15" level="project" />
123+
<orderEntry type="library" scope="RUNTIME" name="Maven: org.apache.ant:ant-antlr:1.9.15" level="project" />
124+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-cli-commons:2.5.14" level="project" />
125+
<orderEntry type="library" name="Maven: commons-cli:commons-cli:1.4" level="project" />
126+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-cli-picocli:2.5.14" level="project" />
127+
<orderEntry type="library" name="Maven: info.picocli:picocli:4.3.2" level="project" />
128+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-console:2.5.14" level="project" />
129+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-datetime:2.5.14" level="project" />
130+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-docgenerator:2.5.14" level="project" />
131+
<orderEntry type="library" name="Maven: com.thoughtworks.qdox:qdox:1.12.1" level="project" />
132+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-groovydoc:2.5.14" level="project" />
133+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-groovysh:2.5.14" level="project" />
134+
<orderEntry type="library" name="Maven: jline:jline:2.14.6" level="project" />
135+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-jmx:2.5.14" level="project" />
136+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-json:2.5.14" level="project" />
137+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-jsr223:2.5.14" level="project" />
138+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-macro:2.5.14" level="project" />
139+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-nio:2.5.14" level="project" />
140+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-servlet:2.5.14" level="project" />
141+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-sql:2.5.14" level="project" />
142+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-swing:2.5.14" level="project" />
143+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-templates:2.5.14" level="project" />
144+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-test:2.5.14" level="project" />
145+
<orderEntry type="library" name="Maven: junit:junit:4.13.1" level="project" />
146+
<orderEntry type="library" name="Maven: org.hamcrest:hamcrest-core:2.2" level="project" />
147+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-test-junit5:2.5.14" level="project" />
148+
<orderEntry type="library" name="Maven: org.junit.platform:junit-platform-launcher:1.7.0" level="project" />
149+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-testng:2.5.14" level="project" />
150+
<orderEntry type="library" scope="RUNTIME" name="Maven: org.testng:testng:6.13.1" level="project" />
151+
<orderEntry type="library" scope="RUNTIME" name="Maven: com.beust:jcommander:1.72" level="project" />
152+
<orderEntry type="library" name="Maven: org.codehaus.groovy:groovy-xml:2.5.14" level="project" />
153+
<orderEntry type="library" name="Maven: org.dom4j:dom4j:2.1.3" level="project" />
154+
<orderEntry type="library" name="Maven: org.jdom:jdom2:2.0.6" level="project" />
155+
<orderEntry type="library" name="Maven: org.xmlbeam:xmlprojector:1.4.14" level="project" />
156+
<orderEntry type="library" name="Maven: io.springfox:springfox-swagger-ui:2.10.5" level="project" />
157+
<orderEntry type="library" name="Maven: io.springfox:springfox-swagger2:2.9.2" level="project" />
158+
<orderEntry type="library" name="Maven: io.swagger:swagger-annotations:1.5.20" level="project" />
159+
<orderEntry type="library" name="Maven: io.swagger:swagger-models:1.5.20" level="project" />
160+
<orderEntry type="library" name="Maven: com.fasterxml.jackson.core:jackson-annotations:2.11.3" level="project" />
161+
<orderEntry type="library" name="Maven: io.springfox:springfox-spi:2.9.2" level="project" />
162+
<orderEntry type="library" name="Maven: io.springfox:springfox-core:2.9.2" level="project" />
163+
<orderEntry type="library" name="Maven: io.springfox:springfox-schema:2.9.2" level="project" />
164+
<orderEntry type="library" name="Maven: io.springfox:springfox-swagger-common:2.9.2" level="project" />
165+
<orderEntry type="library" name="Maven: io.springfox:springfox-spring-web:2.9.2" level="project" />
166+
<orderEntry type="library" name="Maven: com.google.guava:guava:20.0" level="project" />
167+
<orderEntry type="library" name="Maven: com.fasterxml:classmate:1.5.1" level="project" />
168+
<orderEntry type="library" name="Maven: org.slf4j:slf4j-api:1.7.30" level="project" />
169+
<orderEntry type="library" name="Maven: org.springframework.plugin:spring-plugin-core:1.2.0.RELEASE" level="project" />
170+
<orderEntry type="library" name="Maven: org.springframework.plugin:spring-plugin-metadata:1.2.0.RELEASE" level="project" />
171+
<orderEntry type="library" name="Maven: org.mapstruct:mapstruct:1.2.0.Final" level="project" />
172+
<orderEntry type="library" name="Maven: org.jsoup:jsoup:1.12.2" level="project" />
116173
</component>
117174
</module>

media/16261597400147.jpg

-802 KB
Binary file not shown.

media/16278906186353.jpg

1.1 MB
Loading

pom.xml

Lines changed: 58 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@
1111

1212
<groupId>com.best</groupId>
1313
<artifactId>hello</artifactId>
14-
<version>0.0.1-SNAPSHOT</version>
14+
<version>1.0.0-SNAPSHOT</version>
1515
<name>hello java sec</name>
1616
<description>Java Sec</description>
1717
<packaging>jar</packaging>
@@ -72,11 +72,17 @@
7272
<version>1.2.24</version>
7373
</dependency>
7474

75+
<dependency>
76+
<groupId>com.thoughtworks.xstream</groupId>
77+
<artifactId>xstream</artifactId>
78+
<version>1.4.10</version>
79+
</dependency>
80+
7581
<!-- 热启动 -->
7682
<dependency>
7783
<groupId>org.springframework.boot</groupId>
7884
<artifactId>spring-boot-devtools</artifactId>
79-
<optional>true</optional>
85+
<scope>runtime</scope>
8086
</dependency>
8187

8288
<!-- actuator监控 -->
@@ -91,16 +97,66 @@
9197
<version>1.4.0</version>
9298
</dependency>
9399

100+
<dependency>
101+
<groupId>org.apache.logging.log4j</groupId>
102+
<artifactId>log4j-core</artifactId>
103+
</dependency>
104+
105+
<!-- 引入groovy 来执行命令 -->
106+
<dependency>
107+
<groupId>org.codehaus.groovy</groupId>
108+
<artifactId>groovy-all</artifactId>
109+
<version>2.5.6</version>
110+
<type>pom</type>
111+
</dependency>
112+
113+
<!-- 开源的xml解析包 -->
114+
<dependency>
115+
<groupId>org.dom4j</groupId>
116+
<artifactId>dom4j</artifactId>
117+
<version>2.1.3</version>
118+
</dependency>
119+
120+
<dependency>
121+
<groupId>org.jdom</groupId>
122+
<artifactId>jdom2</artifactId>
123+
<version>2.0.6</version>
124+
</dependency>
125+
126+
<!-- xmlbeam xxe漏洞 -->
127+
<dependency>
128+
<groupId>org.xmlbeam</groupId>
129+
<artifactId>xmlprojector</artifactId>
130+
<version>1.4.14</version>
131+
</dependency>
132+
133+
<dependency>
134+
<groupId>io.springfox</groupId>
135+
<artifactId>springfox-swagger-ui</artifactId>
136+
<version>2.10.5</version>
137+
</dependency>
138+
<dependency>
139+
<groupId>io.springfox</groupId>
140+
<artifactId>springfox-swagger2</artifactId>
141+
<version>2.9.2</version>
142+
</dependency>
143+
<dependency>
144+
<groupId>org.jsoup</groupId>
145+
<artifactId>jsoup</artifactId>
146+
<version>1.12.2</version>
147+
</dependency>
94148

95149
</dependencies>
96150

97151
<build>
98152
<plugins>
153+
<!-- 用于maven构建 -->
99154
<plugin>
100155
<groupId>org.springframework.boot</groupId>
101156
<artifactId>spring-boot-maven-plugin</artifactId>
102157
</plugin>
103158
</plugins>
104159
</build>
105160

161+
106162
</project>

0 commit comments

Comments
 (0)