Apache ShardingSphereÔ¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-03-11·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-1947£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Apache ShardingSphere < 4.0.1
·ì϶¸ÅÊö
Apache ShardingSphereÊÇÒ»Ì׿ªÔ´µÄÉ¢²¼Ê½Êý¾Ý¿âÖÐÑë¼þ½â¾ö¹æ»®×é³ÉµÄÉú̬Ȧ£¬ËüÓÉSharding-JDBC¡¢Sharding-ProxyºÍSharding-Sidecar£¨¹æ»®ÖУ©Õâ3¿îÏ໥¶ÀÁ¢£¬È´ÓÖ¿ÉÄÜ»ìºÏ²¿Êð¹²Í¬Ê¹ÓõIJúÆ·×é³É¡£ËüÃǾùÌṩ³ß¶È»¯µÄÊý¾Ý·Ô쬡¢É¢²¼Ê½ÊÂÎñºÍÊý¾Ý¿âÖÎÀíÖ°ÄÜ£¬¿ÉºÏÓÃÓÚÈçJavaͬ¹¹¡¢Ò칹˵»°¡¢ÔÆÔÉúµÈ¸÷Àà¶àÑù»¯µÄÀûÓó¡¾°¡£
Apache ShardingSphere´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¾¹ýÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÌá½»ËÁÒâYAML´úÂëʵÏÖÔ¶³Ì´úÂëÖ´ÐС£Apache ShardingSphereºó¶ÜµÄÖÎÀíÕ˺ÅÃÜÂëĬÈϾùΪadmin¡£
ͨ¹ý¶ÔApache ShardingSphere´úÂë·ÖÎö£¬·¢ÏÖ¿ª·¢ÈËÔ±Ö±½ÓʹÓÃunmarshal²½Öè¶ÔÊäÈëµÄYAMLÖ±½Ó½øÐнâÎö£¬Ã»ÓÐ×öУÑé¡£
¶Ô±È²¹¶¡·¢ÏÖÐÂÔöClassFilterConstructorÀ´¶Ô´Ë½øÐÐУÑé¡£
·ì϶ÑéÖ¤
PoC:https://github.com/Imanfeng/CVE-2020-1947¡£
½¨¸´½¨Òé
Ŀǰ¹Ù·½ÒѰ䲼×îа汾½¨¸´¸Ã·ì϶£¬½¨ÒéÓû§¾¡¿ìÉý¼¶£ºhttps://github.com/apache/incubator-shardingsphere/releases¡£
²Î¿¼Á´½Ó
https://github.com/apache/incubator-shardingsphere/releases


¾©¹«Íø°²±¸11010802024551ºÅ