pom.xml 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431
  1. <?xml version="1.0" encoding="UTF-8"?>
  2. <project xmlns="http://maven.apache.org/POM/4.0.0"
  3. xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
  4. xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
  5. <modelVersion>4.0.0</modelVersion>
  6. <groupId>sec</groupId>
  7. <artifactId>java-sec-code</artifactId>
  8. <version>1.0.0</version>
  9. <packaging>jar</packaging>
  10. <properties>
  11. <maven.compiler.source>1.8</maven.compiler.source> <!-- mvn clean package-->
  12. <maven.compiler.target>1.8</maven.compiler.target>
  13. </properties>
  14. <parent>
  15. <groupId>org.springframework.boot</groupId>
  16. <artifactId>spring-boot-starter-parent</artifactId>
  17. <version>1.5.1.RELEASE</version>
  18. </parent>
  19. <dependencies>
  20. <dependency>
  21. <groupId>org.springframework.boot</groupId>
  22. <artifactId>spring-boot-starter-web</artifactId>
  23. </dependency>
  24. <!-- 添加thymeleaf为了动态解析html-->
  25. <dependency>
  26. <groupId>org.springframework.boot</groupId>
  27. <artifactId>spring-boot-starter-thymeleaf</artifactId>
  28. </dependency>
  29. <!-- 处理jdbc的mysql连接-->
  30. <dependency>
  31. <groupId>mysql</groupId>
  32. <artifactId>mysql-connector-java</artifactId>
  33. <version>8.0.12</version>
  34. </dependency>
  35. <!-- 处理json数据 -->
  36. <!-- https://mvnrepository.com/artifact/com.alibaba/fastjson -->
  37. <dependency>
  38. <groupId>com.alibaba</groupId>
  39. <artifactId>fastjson</artifactId>
  40. <version>1.2.24</version>
  41. </dependency>
  42. <!-- jdom解析xml 最新版本为2.0.6 时间为2015-02-28 https://github.com/hunterhacker/jdom/releases-->
  43. <!-- https://mvnrepository.com/artifact/org.jdom/jdom2 -->
  44. <dependency>
  45. <groupId>org.jdom</groupId>
  46. <artifactId>jdom2</artifactId>
  47. <version>2.0.6</version>
  48. </dependency>
  49. <!-- https://mvnrepository.com/artifact/org.dom4j/dom4j -->
  50. <dependency>
  51. <groupId>org.dom4j</groupId>
  52. <artifactId>dom4j</artifactId>
  53. <version>2.1.0</version>
  54. </dependency>
  55. <!-- 获取url根域名-->
  56. <dependency>
  57. <groupId>com.google.guava</groupId>
  58. <artifactId>guava</artifactId>
  59. <version>23.0</version>
  60. </dependency>
  61. <dependency>
  62. <groupId>commons-collections</groupId>
  63. <artifactId>commons-collections</artifactId>
  64. <version>3.1</version>
  65. </dependency>
  66. <dependency>
  67. <groupId>commons-lang</groupId>
  68. <artifactId>commons-lang</artifactId>
  69. <version>2.4</version> </dependency>
  70. <dependency>
  71. <groupId>org.apache.httpcomponents</groupId>
  72. <artifactId>httpclient</artifactId>
  73. <version>4.5.12</version>
  74. </dependency>
  75. <dependency>
  76. <groupId>org.apache.httpcomponents</groupId>
  77. <artifactId>fluent-hc</artifactId>
  78. <version>4.3.6</version>
  79. </dependency>
  80. <dependency>
  81. <groupId>org.apache.logging.log4j</groupId>
  82. <artifactId>log4j-core</artifactId>
  83. <version>2.9.1</version>
  84. </dependency>
  85. <dependency>
  86. <groupId>org.apache.logging.log4j</groupId>
  87. <artifactId>log4j-api</artifactId>
  88. <version>2.9.1</version>
  89. </dependency>
  90. <dependency>
  91. <groupId>com.squareup.okhttp</groupId>
  92. <artifactId>okhttp</artifactId>
  93. <version>2.5.0</version>
  94. </dependency>
  95. <dependency>
  96. <groupId>org.apache.commons</groupId>
  97. <artifactId>commons-digester3</artifactId>
  98. <version>3.2</version>
  99. </dependency>
  100. <!-- SpringBoot Actuator命令执行的库 -->
  101. <dependency>
  102. <groupId>org.jolokia</groupId>
  103. <artifactId>jolokia-core</artifactId>
  104. <version>1.6.0</version>
  105. </dependency>
  106. <!-- 添加SpringBoot Actuator-->
  107. <dependency>
  108. <groupId>org.springframework.boot</groupId>
  109. <artifactId>spring-boot-starter-actuator</artifactId>
  110. </dependency>
  111. <!-- eureka -->
  112. <dependency>
  113. <groupId>org.springframework.cloud</groupId>
  114. <artifactId>spring-cloud-starter-netflix-eureka-client</artifactId>
  115. <version>1.4.0.RELEASE</version>
  116. </dependency>
  117. <!-- 生成uuid -->
  118. <dependency>
  119. <groupId>com.fasterxml.uuid</groupId>
  120. <artifactId>java-uuid-generator</artifactId>
  121. <version>3.1.4</version>
  122. </dependency>
  123. <!-- 5.x的spring-security版本不适配springboot 1.5,因为1.5的springboot的spring-core版本是4.x,所以spring-security改为4.x即可适配。 -->
  124. <dependency>
  125. <groupId>org.springframework.security</groupId>
  126. <artifactId>spring-security-web</artifactId>
  127. <version>4.2.12.RELEASE</version>
  128. </dependency>
  129. <dependency>
  130. <groupId>org.springframework.security</groupId>
  131. <artifactId>spring-security-config</artifactId>
  132. <version>4.2.12.RELEASE</version>
  133. </dependency>
  134. <dependency>
  135. <groupId>org.springframework.boot</groupId>
  136. <artifactId>spring-boot-starter-security</artifactId>
  137. <version>2.1.5.RELEASE</version>
  138. </dependency>
  139. <dependency>
  140. <groupId>commons-net</groupId>
  141. <artifactId>commons-net</artifactId>
  142. <version>3.6</version>
  143. </dependency>
  144. <!-- HttpClient SSRF -->
  145. <dependency>
  146. <groupId>commons-httpclient</groupId>
  147. <artifactId>commons-httpclient</artifactId>
  148. <version>3.1</version>
  149. </dependency>
  150. <!-- mybatis -->
  151. <dependency>
  152. <groupId>org.mybatis.spring.boot</groupId>
  153. <artifactId>mybatis-spring-boot-starter</artifactId>
  154. <version>1.3.2</version>
  155. </dependency>
  156. <!-- ssti -->
  157. <dependency>
  158. <groupId>org.apache.velocity</groupId>
  159. <artifactId>velocity</artifactId>
  160. <version>1.7</version>
  161. </dependency>
  162. <dependency>
  163. <groupId>com.thoughtworks.xstream</groupId>
  164. <artifactId>xstream</artifactId>
  165. <!-- For testing, you can use the vulnerable version of 1.4.10. -->
  166. <version>1.4.20</version> <!-- use latest version to exploit vuln by using xstream.addPermission-->
  167. </dependency>
  168. <dependency>
  169. <groupId>org.apache.poi</groupId>
  170. <artifactId>poi</artifactId>
  171. <version>3.10-FINAL</version>
  172. </dependency>
  173. <!-- vuln maven jar. Solve xlsx.-->
  174. <dependency>
  175. <groupId>org.apache.poi</groupId>
  176. <artifactId>poi-ooxml</artifactId>
  177. <version>3.9</version> <!-- 3.10-FINAL -->
  178. </dependency>
  179. <dependency>
  180. <groupId>com.monitorjbl</groupId>
  181. <artifactId>xlsx-streamer</artifactId>
  182. <version>2.0.0</version>
  183. </dependency>
  184. <!-- ssrf -->
  185. <dependency>
  186. <groupId>org.jsoup</groupId>
  187. <artifactId>jsoup</artifactId>
  188. <version>1.10.2</version>
  189. </dependency>
  190. <!-- SSRF -->
  191. <dependency>
  192. <groupId>commons-io</groupId>
  193. <artifactId>commons-io</artifactId>
  194. <version>2.5</version>
  195. </dependency>
  196. <!-- SSRF -->
  197. <dependency>
  198. <groupId>org.apache.httpcomponents</groupId>
  199. <artifactId>httpasyncclient</artifactId>
  200. <version>4.1.4</version>
  201. </dependency>
  202. <dependency>
  203. <groupId>io.springfox</groupId>
  204. <artifactId>springfox-swagger2</artifactId>
  205. <version>2.9.2</version>
  206. </dependency>
  207. <dependency>
  208. <groupId>io.springfox</groupId>
  209. <artifactId>springfox-swagger-ui</artifactId>
  210. <version>2.9.2</version>
  211. </dependency>
  212. <!-- https://mvnrepository.com/artifact/org.projectlombok/lombok -->
  213. <dependency>
  214. <groupId>org.projectlombok</groupId>
  215. <artifactId>lombok</artifactId>
  216. <version>1.18.20</version>
  217. <scope>provided</scope>
  218. </dependency>
  219. <dependency>
  220. <groupId>org.yaml</groupId>
  221. <artifactId>snakeyaml</artifactId>
  222. <version>1.21</version>
  223. </dependency>
  224. <dependency>
  225. <groupId>org.springframework</groupId>
  226. <artifactId>spring-test</artifactId>
  227. </dependency>
  228. <dependency>
  229. <groupId>junit</groupId>
  230. <artifactId>junit</artifactId>
  231. </dependency>
  232. <!-- add commons-beanutils gadget -->
  233. <dependency>
  234. <groupId>commons-beanutils</groupId>
  235. <artifactId>commons-beanutils</artifactId>
  236. <version>1.9.4</version>
  237. </dependency>
  238. <!-- https://mvnrepository.com/artifact/io.jsonwebtoken/jjwt -->
  239. <dependency>
  240. <groupId>io.jsonwebtoken</groupId>
  241. <artifactId>jjwt</artifactId>
  242. <version>0.9.1</version>
  243. </dependency>
  244. <!-- https://github.com/auth0/java-jwt https://mvnrepository.com/artifact/com.auth0/java-jwt -->
  245. <dependency>
  246. <groupId>com.auth0</groupId>
  247. <artifactId>java-jwt</artifactId>
  248. <version>4.0.0</version>
  249. </dependency>
  250. <dependency>
  251. <groupId>cn.hutool</groupId>
  252. <artifactId>hutool-all</artifactId>
  253. <version>5.8.10</version>
  254. </dependency>
  255. <dependency>
  256. <groupId>org.javassist</groupId>
  257. <artifactId>javassist</artifactId>
  258. <version>3.27.0-GA</version>
  259. </dependency>
  260. <dependency>
  261. <groupId>org.springframework.data</groupId>
  262. <artifactId>spring-data-commons</artifactId>
  263. <version>1.13.11.RELEASE</version>
  264. </dependency>
  265. <dependency>
  266. <groupId>com.jayway.jsonpath</groupId>
  267. <artifactId>json-path</artifactId>
  268. </dependency>
  269. <dependency>
  270. <groupId>org.xmlbeam</groupId>
  271. <artifactId>xmlprojector</artifactId>
  272. <version>1.4.13</version>
  273. </dependency>
  274. <!-- CVE-2022-21724 -->
  275. <dependency>
  276. <groupId>org.postgresql</groupId>
  277. <artifactId>postgresql</artifactId>
  278. <version>42.3.1</version>
  279. </dependency>
  280. <!-- jdbc db2 rce -->
  281. <dependency>
  282. <groupId>com.ibm.db2</groupId>
  283. <artifactId>jcc</artifactId>
  284. <version>11.5.8.0</version>
  285. </dependency>
  286. <dependency>
  287. <groupId>org.apache.shiro</groupId>
  288. <artifactId>shiro-core</artifactId>
  289. <version>1.2.4</version>
  290. </dependency>
  291. <dependency>
  292. <groupId>com.fasterxml.jackson.core</groupId>
  293. <artifactId>jackson-databind</artifactId>
  294. <version>2.9.8</version>
  295. </dependency>
  296. <dependency>
  297. <groupId>com.fasterxml.jackson.core</groupId>
  298. <artifactId>jackson-annotations</artifactId>
  299. <version>2.9.8</version>
  300. </dependency>
  301. <dependency>
  302. <groupId>com.fasterxml.jackson.core</groupId>
  303. <artifactId>jackson-core</artifactId>
  304. <version>2.9.8</version>
  305. </dependency>
  306. <!-- https://mvnrepository.com/artifact/org.jsecurity/jsecurity -->
  307. <dependency>
  308. <groupId>org.jsecurity</groupId>
  309. <artifactId>jsecurity</artifactId>
  310. <version>0.9.0</version>
  311. </dependency>
  312. <!-- 为了使用SimpleEvaluationContext,该类需要spring-expression版本大于等于4.3.15 -->
  313. <dependency>
  314. <groupId>org.springframework</groupId>
  315. <artifactId>spring-expression</artifactId>
  316. <version>4.3.16.RELEASE</version>
  317. </dependency>
  318. <!-- https://mvnrepository.com/artifact/com.h2database/h2 -->
  319. <dependency>
  320. <groupId>com.h2database</groupId>
  321. <artifactId>h2</artifactId>
  322. <version>1.4.199</version>
  323. <scope>test</scope>
  324. </dependency>
  325. <dependency>
  326. <groupId>org.apache.tomcat</groupId>
  327. <artifactId>tomcat-dbcp</artifactId>
  328. <version>9.0.8</version>
  329. </dependency>
  330. <dependency>
  331. <groupId>com.alibaba</groupId>
  332. <artifactId>QLExpress</artifactId>
  333. <version>3.3.1</version>
  334. </dependency>
  335. </dependencies>
  336. <dependencyManagement>
  337. <dependencies>
  338. <dependency>
  339. <groupId>org.springframework.cloud</groupId>
  340. <artifactId>spring-cloud-dependencies</artifactId>
  341. <version>Camden.RELEASE</version>
  342. <type>pom</type>
  343. <scope>import</scope>
  344. </dependency>
  345. </dependencies>
  346. </dependencyManagement>
  347. <!-- jar -->
  348. <build>
  349. <plugins>
  350. <plugin>
  351. <groupId>org.springframework.boot</groupId>
  352. <artifactId>spring-boot-maven-plugin</artifactId>
  353. </plugin>
  354. </plugins>
  355. </build>
  356. </project>