Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[ 问题咨询 ]1.7.7archery存在sql注入风险,已被安全检测,可否消除这个隐患 #979

Closed
mingjia1 opened this issue Dec 2, 2020 · 5 comments · Fixed by #981
Labels
question Further information is requested

Comments

@mingjia1
Copy link

mingjia1 commented Dec 2, 2020

问题描述

ip:port/instance/instance_resource/?db_name=rural_house_census_pro&instance_name=库名&resource_type=column&schema_name=&tb_name=表明
上述链接被安全检测出安全漏洞,这个问题能否解决

版本信息

  • 应用版本/分支:Release v1.7.7
  • 部署方式:手工部署
@mingjia1 mingjia1 added the question Further information is requested label Dec 2, 2020
@LeoQuote
Copy link
Collaborator

LeoQuote commented Dec 2, 2020

能不能详细提供一下 sql 注入的方式, 或者安全检测工具以及详细的报告?

@hhyo
Copy link
Owner

hhyo commented Dec 2, 2020

使用sql拼接并且接受传参的方式都会存在这个隐患,可以集中处理一下

@LeoQuote
Copy link
Collaborator

LeoQuote commented Dec 2, 2020

一般是咋处理? 接个第三方的库吗?

@mingjia1
Copy link
Author

mingjia1 commented Dec 3, 2020

我有报告怎么提交给你

@mingjia1
Copy link
Author

mingjia1 commented Dec 3, 2020

@hhyo hhyo closed this as completed in #981 Dec 6, 2020
hhyo added a commit that referenced this issue Dec 6, 2020
对接受入参的SQL拼接增加参数转义,规避注入风险 fix #979
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants