Apache SolrÔ¶³ÌºÅÁîÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-08-07? ·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-0193£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
? Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
ºÏÓÃÓÚApache Solr < 8.2.0¡£
? ·ì϶¸ÅÊö
Apache SolrÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î»ùÓÚLucene£¨Ò»¿îÈ«ÎÄËÑË÷ÒýÇæ£©µÄËÑË÷·þÎñÆ÷¡£¸Ã²úÆ·Ö§³Ö²ãÃæËÑË÷¡¢´¹Ö±ËÑË÷¡¢¸ßÁÁÏÔʾËÑË÷Á˾ֵȡ£
Õâ´Î·ì϶³Ê´Ë¿ÌApache SolrµÄDataImportHandler£¬¸ÃÄ£¿éÊÇÒ»¸ö¿ÉÑ¡µ«³£ÓõÄÄ£¿é£¬ÓÃÓÚ´ÓÊý¾Ý¿âºÍÆäËûÔ´ÖÐÌáÈ¡Êý¾Ý¡£
¸Ã·ì϶ԴÓÚÓû§ÔÚsolrconfig.xmlÎļþÖÐÉèÖÃÁËDataImportHandler£¬¿ªÆôÁËDataImportÖ°ÄÜ¡£DataImportHandlerÄ£¿éÔÊÐíÓû§×Ô¼ºÔ̺¬¾ç±¾£¬À´½øÐÐÅäÖ᣹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâµÄ¾ç±¾½»ÓÉת»»Æ÷½øÐнâÎö£¬ÔÚSolr½âÎöµÄ¹ý³ÌÖв¢Î´¶ÔÓû§µÄÊäÈë×ö²é³£¬¿Éµ¼Ö¹¥»÷ÕßÔ¶³ÌÔÚSolr·þÎñÆ÷ÉÏÖ´ÐкÅÁî¡£
? ·ì϶ÑéÖ¤
EXP: https://github.com/xConsoIe/CVE-2019-0193¡£
? ½¨¸´½¨Òé
½«Apache SolrÉý¼¶ÖÁ8.2.0»ò¸ü¸ßµÄ°æ±¾¡£
һʱ½¨¸´½¨Ò飺
1¡¢±à×ësolrconfig.xml£¬½«ËùÓÐЧ¹Ì¶¨ÖµÅäÖõÄDataImportHandlerÓ÷¨ÖеÄdataConfig²ÎÊýÉèÖÃΪ¿Õ×Ö·û´®£»
2¡¢È·±£ÍøÂçÉèÖÃÖ»ÔÊÐí¿ÉÐŵÄÁ÷Á¿ÓëSolr½øÐÐͨѶ£¬³ö¸ñÊÇÓëDIHÒªÇó´¦Ö÷¨Ê½µÄͨѶ¡£
? ²Î¿¼Á´½Ó
https://issues.apache.org/jira/browse/SOLR-13669


¾©¹«Íø°²±¸11010802024551ºÅ