Spring Data CommonsÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-1273£©
2018-04-12
Pivotal Spring¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬Spring Data Commons×é¼þÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-1273£©£¬¹¥»÷Õ߿ɽṹ°üÀ¨ÓжñÒâ´úÂëµÄSPEL±í´ïʽʵÏÖÔ¶³Ì´úÂë¹¥»÷£¬Ö±½Ó»ñÈ¡·þÎñÆ÷¿ØÖÆÈ¨ÏÞ¡£
Spring DataÊÇÒ»¸öÓÃÓÚ¼ò»¯Êý¾Ý¿â»á¼û£¬²¢Ö§³ÖÔÆ·þÎñµÄ¿ªÔ´¿ò¼Ü°üÀ¨Commons¡¢Gemfire¡¢JPA¡¢JDBC¡¢MongoDBµÈÄ£¿é¡£´ËÎó²î±¬·¢ÓÚSpring Data Commons×é¼þ£¬¸Ã×é¼þΪÌṩ¹²ÏíµÄ»ù´¡¿ò¼Ü£¬Êʺϸ÷¸ö×ÓÏîĿʹÓã¬Ö§³Ö¿çÊý¾Ý¿â³¤ÆÚ»¯¡£ÇëÊÜ´ËÎó²îÓ°ÏìÓû§¾¡¿ìÉý¼¶×é¼þ¡£
ÏêÇéÇë²Î¿¼ÈçÏÂÁ´½Ó£º
https://pivotal.io/security/cve-2018-1273
CVE-2018-1273 Îó²îÓ°Ïì
ÊÜÓ°ÏìµÄ°æ±¾
- Spring Data Commons 1.13 - 1.13.10 (Ingalls SR10)
- Spring Data REST 2.6 - 2.6.10(Ingalls SR10)
- Spring Data Commons 2.0 - 2.0.5 (Kay SR5)
- Spring Data REST 3.0 - 3.0.5(Kay SR5)
- ¹Ù·½ÒѾ²»Ö§³ÖµÄ¾É°æ±¾
²»ÊÜÓ°ÏìµÄ°æ±¾
- Spring Data Commons ¡Ý 2.0.6
- Spring Data Commons ¡Ý 1.13.11
- Spring Data REST 2.6.11 (Ingalls SR11)
- Spring Data REST 3.0.6 (Kay SR6)
- Spring Boot 1.5.11
- Spring Boot 2.0.1
CVE-2018-1273 Ó°ÏìÅŲé
Îó²î±¬·¢ÓÚSpring Data Commons×é¼þ£¬¹ØÓÚʹÓÃSpring¿ò¼ÜµÄÓ¦ÓÃϵͳ£¬ÇëÉó²éÓ¦ÓÃÖеÄ×é¼þ°æ±¾ÊÇ·ñÔÚÊÜÓ°Ïì¹æÄ£ÄÚ¡£Ê¹ÓÃÎı¾±à¼Æ÷·¿ªpom.xml£¬ÕÒµ½ÏÂͼºì¿òËùʾ²¿·ÖÉó²éÄ¿½ñµÄ°æ±¾ÐÅÏ¢¡£
ÈôÊÇÄ¿½ñ°æ±¾ÔÚÊÜÓ°Ïì¹æÄ£ÄÚ£¬Ôò±£´æÎó²îΣº¦£¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±¾ÙÐмӹ̡£
CVE-2018-1273 Îó²î·À»¤
¹Ù·½ÒѾÔÚ×îа汾ÖÐÐÞ¸´Á˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶£¬ÒÔ°ü¹Üºã¾ÃÓÐÓõķÀ»¤¡£ÏÂÔØÁ´½ÓÇë²Î¿¼ÏÂ±í£º
|
×é¼þ°æ±¾ |
ÏÂÔØÁ´½Ó |
| Spring Data Commons 2.0.6 | https://github.com/spring-projects/spring-data-commons/archive/2.0.6.RELEASE.zip |
| Spring Data Commons 1.13.11 | https://github.com/spring-projects/spring-data-commons/archive/1.13.11.RELEASE.zip |
| Spring Data REST 3.0.6 | https://github.com/spring-projects/spring-data-rest/archive/3.0.6.RELEASE.zip |
| Spring Data REST 2.6.11 | https://github.com/spring-projects/spring-data-rest/archive/2.6.11.RELEASE.zip |
| Spring Boot 2.0.1 | https://github.com/spring-projects/spring-boot/archive/v2.0.1.RELEASE.zip |
| Spring Boot 1.5.11 | https://github.com/spring-projects/spring-boot/archive/v1.5.11.RELEASE.zip |

¾ÅÓÎÀϸçÔÆ





