Conversation

I accidentally saw that apache commons text component suddenly made an update (Figure 1) On the official website we can see (Figure 2) What exactly has been disabled? And how did it behave in previous versions? (Figure 3) Ps: not yet seen CVE, guess on the way,hhh
Image
Image
Image
3
49
Replying to
<=1.9.0存在,1.10.0中resolveVariable那个方法调用里面不能获取到ScriptLookup了,其他几个昨天试了下,没太大利用点。。。
1