Apache Struts2£¨S2-048£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î ÍþвԤ¾¯Í¨¸æ
2017-07-08
2017Äê7ÔÂ7ÈÕ£¬Apache StrutsÐû²¼×îеÄÇ徲ͨ¸æ£¬Apache Structs2µÄstrus1²å¼þ±£´æÔ¶³Ì´úÂëÖ´ÐеĸßΣÎó²î£¬Îó²î±àºÅΪCVE-2017-9791£¨S2-048£©¡£¹¥»÷Õß¿ÉÒԽṹ¶ñÒâµÄ×Ö¶Îֵͨ¹ýStruts2µÄStruts1µÄ²å¼þ£¬Ô¶³ÌÖ´ÐдúÂë¡£
Ïà¹ØÁ´½ÓÈçÏ£º
https://cwiki.apache.org/confluence/display/WW/S2-048
Ó°Ïì°æ±¾£º
Apache Struts Version£º2.3.x
²»ÊÜÓ°ÏìµÄ°æ±¾£º
Apache Struts Version£º2.5.10.1
¹æ±Ü¼Æ»®
¡¤ ¹Ø±ÕShowcase²å¼þ¡£
¡¤ ÊÜÓ°ÏìµÄÓû§¿ÉÒÔÉý¼¶µ½2.5.10.1°æ±¾¡£
¡¤ ¿ª·¢Õßͨ¹ýʹÓÃresource keysÌæ»»½«ÔʼÐÂÎÅÖ±½Óת´ï¸øActionMessageµÄ·½·¨¡£ ÈçÏÂËùʾ£º
²»ÒªÊ¹ÓÃÈçÏµķ½·¨£º
¡¤ ÔÚ·ÇÐëÒªµÄÇéÐÎϽûÓÃstruts2-struts1-plugin²å¼þ¡£½«struts2-struts1-plugin-2.3.x.jarÎļþ´Ó ¡°/WEB-INF/lib¡±Ä¿Â¼ÖÐÒÆ¶¯µ½ÆäËûÎļþ¼Ð»òÕßɾ³ý¡£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ







