Spring Data Rest·þÎñÆ÷PATCHÇëÇóÔ¶³Ì´úÂëÖ´ÐÐÎó²î CVE-2017-8046
2017-09-29
×ÛÊö
¿ËÈÕ£¬Pivotal¹Ù·½Ðû²¼Í¨¸æÌåÏÖSpring-data-rest·þÎñÆ÷ÔÚ´¦Öóͷ£PATCHÇëÇóʱ±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2017-8046£©¡£¹¥»÷Õß¿ÉÒԽṹ¶ñÒâµÄPATCHÇëÇó²¢·¢Ë͸øspring-date-rest·þÎñÆ÷£¬Ìá½»µÄJSONÊý¾ÝÖб£´æSPEL±í´ïʽ¿ÉÒÔµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¹Ù·½ÒѾÐû²¼ÁËа汾ÐÞ¸´Á˸ÃÎó²î¡£
Ïà¹ØµØµã£º
https://pivotal.io/security/cve-2017-8046
ÊÜÓ°ÏìµÄ°æ±¾
¡¤ Spring Data REST versions < 2.5.12 2.6.7 3.0 RC3
¡¤ Spring Boot version < 2.0.0M4
¡¤ Spring Data release trains < Kay-RC3
²»ÊÜÓ°ÏìµÄ°æ±¾
¡¤ Spring Data REST 2.5.12 2.6.7 3.0RC3
¡¤ Spring Boot 2.0.0.M4
¡¤ Spring Data release train Kay-RC3
½â¾ö¼Æ»®
¹Ù·½ÒѾÐû²¼ÁËа汾ÐÞ¸´Á˸ÃÎó²î£¬ÊÜÓ°ÏìµÄÓû§Ç뾡¿ìÉý¼¶ÖÁ×îаæÔÀ´·À»¤¸ÃÎó²î¡£
²Î¿¼Á´½Ó
https://projects.spring.io/spring-data-rest/
https://projects.spring.io/spring-boot/
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ







