Apache Struts2£¨S2-052£© Ô¶³Ì´úÂëÖ´ÐÐÎó²î ÍþвԤ¾¯Í¨¸æ
2017-09-06
×ÛÊö
2017Äê9ÔÂ5ÈÕ£¬Apache StrutsÐû²¼×îеÄÇ徲ͨ¸æ£¬Apache Struts 2.5.xµÄREST²å¼þ±£´æÔ¶³Ì´úÂëÖ´ÐеĸßΣÎó²î£¬Îó²î±àºÅΪCVE-2017-9805£¨S2-052£©¡£Îó²îµÄ³ÉÒòÊÇÓÉÓÚʹÓÃXStreamHandler·´ÐòÁл¯XStreamʵÀýµÄʱ¼äûÓÐÈκÎÀàÐ͹ýÂ˵¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
Ïà¹ØÁ´½ÓÈçÏ£º
https://cwiki.apache.org/confluence/display/WW/S2-052
Ó°Ïì°æ±¾
Struts 2.5 - Struts 2.5.12
¹æ±Ü¼Æ»®
Á¬Ã¦Éý¼¶µ½Struts 2.5.13¡£
×¢ÖØ£º
а汾ʹÓõÄĬÈÏÏÞÖÆÕ½ÂԻᵼÖÂRESTµÄһЩº¯Êý×èÖ¹ÊÂÇ飬»á¶ÔһЩӪҵÔì³ÉÓ°Ï죬½¨ÒéʹÓÃÒÔÏÂеĽӿڣº
¡ìorg.apache.struts2.rest.handler.AllowedClasses
¡ìorg.apache.struts2.rest.handler.AllowedClassNames
¡ìorg.apache.struts2.rest.handler.XStreamPermissionProvider
ÔÝʱÐÞ¸´¼Æ»®
1.×èֹʹÓÃREST²å¼þ¡£
2.ÏÞÖÆ·þÎñ¶ËÀ©Õ¹ÀàÐÍ:
<constant name="struts.action.extension" value="xhtmljson" />
Éù Ã÷
==============
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ







