You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot项目引入JDBC Starter出现传递性漏洞依赖原因咨询

问题解析:Spring Boot Starter JDBC依赖的安全漏洞告警

问题说明

你引入的Spring Boot Starter JDBC依赖:

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-jdbc</artifactId>
    <version>3.1.3</version>
</dependency>

在IntelliJ中触发了安全扫描告警,提示内容:

Provides transitive vulnerable dependency org.yaml:snakeyaml:1.33 CVE-2022-41854 6.5 Out-of-bounds Write vulnerability with medium severity found CVE-2022-1471 9.8 Deserialization of Untrusted Data vulnerability with high severity found  Results powered by Checkmarx(c)

这是因为该starter依赖间接引入了存在安全漏洞的snakeyaml 1.33版本,两个漏洞的具体影响:

  • CVE-2022-41854:中等严重度的越界写入漏洞,攻击者可构造恶意YAML数据触发内存越界,导致程序崩溃或执行恶意代码
  • CVE-2022-1471:高严重度的不可信数据反序列化漏洞,攻击者可通过恶意YAML payload实现远程代码执行,风险极高

为什么空项目会出现该告警

Spring Boot的starter依赖是“一站式”依赖包,会自动引入一系列相关的核心子依赖(传递依赖)。spring-boot-starter-jdbc必然会引入Spring Boot核心框架依赖,而snakeyaml是Spring Boot处理YAML配置文件的核心组件——即使你创建的是“空项目”,只要引入了任何Spring Boot starter,都会间接拉取snakeyaml依赖。

你使用的Spring Boot 3.1.3版本默认关联的snakeyaml版本是1.33,恰好存在上述两个已公开的安全漏洞,因此IntelliJ集成的Checkmarx扫描工具会触发黄色告警。

解决办法

  • 直接升级Spring Boot版本到3.2.x及以上的稳定版:Spring Boot官方会在新版本中自动替换为修复了漏洞的snakeyaml版本(如1.34及更高)
  • 在pom.xml中显式声明snakeyaml的安全版本,覆盖传递依赖:
<dependency>
    <groupId>org.yaml</groupId>
    <artifactId>snakeyaml</artifactId>
    <version>2.2</version> <!-- 选择已修复漏洞的稳定版本 -->
</dependency>

内容的提问来源于stack exchange,提问作者Damian

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 20:40:04