Apache Synapse Ô¶³Ì´úÂëÖ´ÐÐÎó²î £¨CVE-2017-15708£©
2017-12-11
×ÛÊö
¿ËÈÕ£¬Apache SynapseÐû²¼ÁËа汾ÐÞ¸´ÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2017-15708£©¡£¸ÃÎó²îÔ´ÓÚApache Commons Collections×é¼þ£¬¹¥»÷Õß¿ÉÒÔͨ¹ý×¢ÈëÌØÖÆµÄÐòÁл¯¹¤¾ßÀ´Ô¶³ÌÖ´ÐдúÂë¡£
Ïà¹ØÁ´½Ó£º
http://www.openwall.com/lists/oss-security/2017/12/10/4?from=timeline
https://commons.apache.org/proper/commons-collections/security-reports.html
ÊÜÓ°ÏìµÄ°æ±¾
Apache Synapse version < 3.0.1
²»ÊÜÓ°ÏìµÄ°æ±¾
Apache Synapse version 3.0.1
½â¾ö¼Æ»®
Apache Synapse¹Ù·½ÒѾÐû²¼ÁË×îеÄ3.0.1°æ±¾ÐÞ¸´Á˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶µ½×îа汾¾ÙÐзÀ»¤¡£
²Î¿¼Á´½Ó£º
http://synapse.apache.org/ #
¹ØÓÚApache Synapse
Apache SynapseÊÇÒ»¸öÇáÁ¿¼¶ÇÒ¸ßÐÔÄܵįóÒµ·þÎñ×ÜÏߣ¨ESB£©¡£ Apache SynapseÓÉ¿ìËÙÒì²½ÖнéÒýÇæÌṩ֧³Ö£¬ÎªXML£¬Web·þÎñºÍRESTÌṩÁË׿ԽµÄÖ§³Ö¡£ ³ýÁËXMLºÍSOAP£¬Apache Synapse»¹Ö§³ÖÆäËû¼¸ÖÖÄÚÈݽ»Á÷ÃûÌã¬Èç´¿Îı¾£¬¶þ½øÖÆ£¬HessianºÍJSON¡£ ¿ÉÓÃÓÚSynapseµÄÖÖÖÖ´«ÊäÊÊÅäÆ÷ʹÆäÄܹ»Í¨¹ýÐí¶àÓ¦ÓòãºÍ´«Êä²ãÐÒé¾ÙÐÐͨѶ¡£ ×èÖ¹ÏÖÔÚ£¬Apache SynapseÖ§³ÖHTTP / S£¬Óʼþ£¨POP3£¬IMAP£¬SMTP£©£¬JMS£¬TCP£¬UDP£¬VFS£¬SMS£¬XMPPºÍFIX¡£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ





