> For the complete documentation index, see [llms.txt](https://docs.keeper.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeper.io/release-notes/jp/developer-tools/automator/automator-version-17.1.2.md).

# オートメーター 17.1.2

本リリースは、第三者によるペネトレーションテストで報告された複数の問題およびライブラリの依存関係への対応を中心としたセキュリティリリースです。すべてのオートメーター環境を、できるだけ早く、または次回の定期メンテナンス時にバージョン17.1.2へアップグレードしてください。

ドキュメントに記載のとおり、すべてのオートメーター環境が推奨される[受信要件](/sso-connect-cloud/jp/device-approvals/automator/ingress-requirements.md)に準拠し、すべての受信トラフィックがKeeperのインフラストラクチャからの通信のみに制限されていることを確認してください。

### セキュリティアップデート <a href="#security-updates" id="security-updates"></a>

* **KAA-167: デシリアライゼーションの強化**\
  Javaのデシリアライゼーション経路に、厳密な `ObjectInputFilter` の許可リストを適用し、オブジェクトのデシリアライズ時に信頼されていないクラスがインスタンス化されることを防止しました。Keeper、Protobuf、BouncyCastle、Keycloak、および必要最小限のJDKプリミティブ型/コレクションなど、明示的に許可されたパッケージのみが受け入れられるようになりました。
* **KAA-167: パストラバーサル対策**\
  SSLパスワードファイルのパス設定で、解決後のパスを正規化し、オートメーターの作業ディレクトリ外を参照するパスを拒否するようになりました。これにより、ローカルファイルリソースを対象としたディレクトリトラバーサル攻撃を防止します。
* **サードパーティライブラリの依存関係:** 通常のSDLCプロセスに従い、47件のライブラリ依存関係をアップグレード。

### アップデート手順 <a href="#update-instructions" id="update-instructions"></a>

{% hint style="warning" %}
バージョン17.1.2へのアップデートでは、暗号化の変更により再初期化が必要です。
{% endhint %}

* コンテナ環境でのデプロイの場合、コンテナを更新しサービスを再起動してください。その後、ご利用のデプロイ方法に応じた[インストール方法](/sso-connect-cloud/jp/device-approvals/automator.md#installation-options)の該当セクションに記載のとおり、**automator setup**に続けて**automator init**を実行してください。
* その他のデプロイ方法でのアップデート手順について詳しくは[こちら](/sso-connect-cloud/jp/device-approvals/automator.md)のページをご参照ください。

### 高度な機能 <a href="#advanced-features" id="advanced-features"></a>

オートメーターサービスの新機能や詳細な設定については、[こちら](/sso-connect-cloud/jp/device-approvals/automator/advanced-settings.md)のページをご参照ください。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.keeper.io/release-notes/jp/developer-tools/automator/automator-version-17.1.2.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
