Browse Source

fix 修复 poi 组件漏洞 与 mysql jdbc 漏洞

疯狂的狮子Li 3 years ago
parent
commit
adf329cf1a
2 changed files with 9 additions and 1 deletions
  1. 8 0
      pom.xml
  2. 1 1
      ruoyi-extend/ruoyi-xxl-job-admin/pom.xml

+ 8 - 0
pom.xml

@@ -23,6 +23,7 @@
         <knife4j.version>3.0.3</knife4j.version>
         <swagger-annotations.version>1.5.22</swagger-annotations.version>
         <poi.version>4.1.2</poi.version>
+        <commons-compress.version>1.21</commons-compress.version>
         <easyexcel.version>3.0.5</easyexcel.version>
         <cglib.version>3.3.0</cglib.version>
         <velocity.version>2.3</velocity.version>
@@ -109,6 +110,13 @@
                 <version>${poi.version}</version>
             </dependency>
 
+            <!-- 修复poi漏洞 -->
+            <dependency>
+                <groupId>org.apache.commons</groupId>
+                <artifactId>commons-compress</artifactId>
+                <version>${commons-compress.version}</version>
+            </dependency>
+
             <dependency>
                 <groupId>com.alibaba</groupId>
                 <artifactId>easyexcel</artifactId>

+ 1 - 1
ruoyi-extend/ruoyi-xxl-job-admin/pom.xml

@@ -11,7 +11,7 @@
 
     <properties>
         <mybatis-spring-boot-starter.version>2.1.4</mybatis-spring-boot-starter.version>
-        <mysql-connector-java.version>8.0.23</mysql-connector-java.version>
+        <mysql-connector-java.version>8.0.28</mysql-connector-java.version>
     </properties>
 
     <dependencyManagement>