Spring Boot项目引入JDBC Starter出现传递性漏洞依赖原因咨询
问题解析:Spring Boot Starter JDBC依赖的安全漏洞告警
问题说明
你引入的Spring Boot Starter JDBC依赖:
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-jdbc</artifactId> <version>3.1.3</version> </dependency>
在IntelliJ中触发了安全扫描告警,提示内容:
Provides transitive vulnerable dependency org.yaml:snakeyaml:1.33 CVE-2022-41854 6.5 Out-of-bounds Write vulnerability with medium severity found CVE-2022-1471 9.8 Deserialization of Untrusted Data vulnerability with high severity found Results powered by Checkmarx(c)
这是因为该starter依赖间接引入了存在安全漏洞的snakeyaml 1.33版本,两个漏洞的具体影响:
- CVE-2022-41854:中等严重度的越界写入漏洞,攻击者可构造恶意YAML数据触发内存越界,导致程序崩溃或执行恶意代码
- CVE-2022-1471:高严重度的不可信数据反序列化漏洞,攻击者可通过恶意YAML payload实现远程代码执行,风险极高
为什么空项目会出现该告警
Spring Boot的starter依赖是“一站式”依赖包,会自动引入一系列相关的核心子依赖(传递依赖)。spring-boot-starter-jdbc必然会引入Spring Boot核心框架依赖,而snakeyaml是Spring Boot处理YAML配置文件的核心组件——即使你创建的是“空项目”,只要引入了任何Spring Boot starter,都会间接拉取snakeyaml依赖。
你使用的Spring Boot 3.1.3版本默认关联的snakeyaml版本是1.33,恰好存在上述两个已公开的安全漏洞,因此IntelliJ集成的Checkmarx扫描工具会触发黄色告警。
解决办法
- 直接升级Spring Boot版本到3.2.x及以上的稳定版:Spring Boot官方会在新版本中自动替换为修复了漏洞的
snakeyaml版本(如1.34及更高) - 在
pom.xml中显式声明snakeyaml的安全版本,覆盖传递依赖:
<dependency> <groupId>org.yaml</groupId> <artifactId>snakeyaml</artifactId> <version>2.2</version> <!-- 选择已修复漏洞的稳定版本 --> </dependency>
内容的提问来源于stack exchange,提问作者Damian
相关产品推荐
相关产品推荐

